On 11/30/05, Szasz Revai Endre <[EMAIL PROTECTED]> wrote: > Hello again! > > About this old problem with the static arp entries.. > 20223 deny ip from 192.168.22.201 not MAC any 00:02:00:25:00:b6 any layer2 in > 20223 deny ip from any to 192.168.22.201 not MAC 00:02:00:25:00:b6 any > layer2 out > There are these things in the ipfw list.. Don't these manage to get > the same level of protection? > In either case, if this works correctly.. Static arp entries could be > changed with a little trick.. We could deny all other macs from the > rest of the network not having a mac like ff:ff:ff:ff:ff.
Yes, but we're trying to get rid of ipfw. It's snuck back in for a few things due to issues with pf for which the easy fix is ipfw. --Bill --------------------------------------------------------------------- To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]
