ipfw and MAC-keyword: unknown arg; but it is in man page!

2004-05-03 Thread Rob
Hi,

With my ipfw firewall, I try to use the MAC keyword, as explained
in the ipfw man page:
--
# man ipfw
[...]
{ MAC | mac } dst-mac src-mac
  Match packets with a given dst-mac and src-mac addresses, speci-
  fied as the any keyword (matching any MAC address), or six groups
  of hex digits separated by colons, and optionally followed by a
  mask indicating how many bits are significant, as in
   MAC 10:20:30:40:50:60/33 any
--
But to no avail:

# ipfw add 900 allow udp from any to any MAC 00:a0:b0:0e:3a:95 any
ipfw: unknown argument ``MAC''
#
Is this a bug, or what?

I use FreeBSD 4.9-stable.

Regards,
Rob.
___
[EMAIL PROTECTED] mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to [EMAIL PROTECTED]


Re: ipfw and MAC-keyword: unknown arg; but it is in man page!

2004-05-03 Thread Matthew Seaman
On Mon, May 03, 2004 at 05:51:26PM +0900, Rob wrote:

 With my ipfw firewall, I try to use the MAC keyword, as explained
 in the ipfw man page:

 But to no avail:
 
 # ipfw add 900 allow udp from any to any MAC 00:a0:b0:0e:3a:95 any
 ipfw: unknown argument ``MAC''
 #
 
 Is this a bug, or what?

That's definitely a 'what'.  MAC header filtering is an IPFW2 feature
and that has to be enabled specially on 4-STABLE.  Read the sections
in ipfw(8) called IPFW2 ENHANCEMENTS and then follow the
instructions in the section USING IPFW2 IN FreeBSD-STABLE

Cheers,

Matthew

-- 
Dr Matthew J Seaman MA, D.Phil.   26 The Paddocks
  Savill Way
PGP: http://www.infracaninophile.co.uk/pgpkey Marlow
Tel: +44 1628 476614  Bucks., SL7 1TH UK


pgp0.pgp
Description: PGP signature