On 11/30/05, Szasz Revai Endre <[EMAIL PROTECTED]> wrote:
> Hello again!
>
> About this old problem with the static arp entries..
> 20223 deny ip from 192.168.22.201 not MAC any 00:02:00:25:00:b6 any layer2 in
> 20223 deny ip from any to 192.168.22.201 not MAC 00:02:00:25:00:b6 any
> layer2 out
> There are these things in the ipfw list.. Don't these manage to get
> the same level of protection?
> In either case, if this works correctly.. Static arp entries could be
> changed with a little trick.. We could deny all other macs from the
> rest of the network not having a mac like ff:ff:ff:ff:ff.

Yes, but we're trying to get rid of ipfw.  It's snuck back in for a
few things due to issues with pf for which the easy fix is ipfw.

--Bill

---------------------------------------------------------------------
To unsubscribe, e-mail: [EMAIL PROTECTED]
For additional commands, e-mail: [EMAIL PROTECTED]

Reply via email to