amd64/97504: IPFW Rules bug

Marcelo Machado marcelo_vt at hotmail.com
Sat May 20 06:20:21 PDT 2006


The following reply was made to PR amd64/97504; it has been noted by GNATS.

From: "Marcelo Machado" <marcelo_vt at hotmail.com>
To: <bug-followup at FreeBSD.org>
Cc:  
Subject: RE: Re: amd64/97504: IPFW Rules bug
Date: Sat, 20 May 2006 13:12:54 +0000

 --_d6bc2cbb-35e5-41b5-9720-9114e24f7867_
 Content-Type: text/plain; charset="iso-8859-1"
 Content-Transfer-Encoding: quoted-printable
 
 Thanks for the assistance Oliver!
 =20
 =20
 But, I have a question, I'm only using IP's and not names, still they look =
 for the DNS?
 =20
 How can I fix it? My firewall is Freebsd 6 and the Dataserver and most of W=
 ebservers are Windows and one Linux.
 =20
 Thanks a Lot!!
 =20
 Best Regards,
 Marcelo
 
 
 
 > Date: Sat, 20 May 2006 13:28:29 +0200> From: olli at lurza.secnetix.de> To: =
 bug-followup at FreeBSD.org; marcelo_vt at hotmail.com> Subject: Re: amd64/97504:=
  IPFW Rules bug> > Marcelo Machado <marcelo_vt at hotmail.com> wrote:>  > > Nu=
 mber:         97504>  > > Synopsis:       IPFW Rules bug>  > > [...]>  > I'=
 ve added the following rules to the ipfw.rules:>  > >  > ipfw add 100 allow=
  all from 192.168.100.3 to 192.168.100.4>  > ipfw add 110 allow all from 19=
 2.168.100.4 to 192.168.100.3>  > ipfw add 65535 deny all from any to any > =
  > >  > With these rules the 192.168.100.3 should ping or interact with>  >=
  192.168.100.4 normally, but don't. But if I add this line:>  > >  > ipfw a=
 dd 1 allow all from any to any>  > >  > they talk each other normally, but =
 the most problem comes next,>  > if I:>  > >  > ipfw delete 1>  > >  > Ever=
 ything begins to work as they should, only these IP's can talk>  > with eac=
 h other on the net.> > You probably forgot to allow access to/from your DNS=
  server,> or something similar.  The rule #1 will shortly allow that> acces=
 s, and when you delete that rule again, it still works> because the DNS res=
 ults are cached.> > Best regards>    Oliver> > -- > Oliver Fromme,  secneti=
 x GmbH & Co. KG, Marktplatz 29, 85567 Grafing> Dienstleistungen mit Schwerp=
 unkt FreeBSD: http://www.secnetix.de/bsd> Any opinions expressed in this me=
 ssage may be personal to the author> and may not necessarily reflect the op=
 inions of secnetix in any way.> > "I made up the term 'object-oriented', an=
 d I can tell you> I didn't have C++ in mind.">         -- Alan Kay, OOPSLA =
 '97
 _________________________________________________________________
 MSN Busca: f=E1cil, r=E1pido, direto ao ponto.=20
 http://search.msn.com.br=
 
 --_d6bc2cbb-35e5-41b5-9720-9114e24f7867_
 Content-Type: text/html; charset="iso-8859-1"
 Content-Transfer-Encoding: quoted-printable
 
 <html>=0A=
 <head>=0A=
 <style>=0A=
 P=0A=
 {=0A=
 margin:0px;=0A=
 padding:0px=0A=
 }=0A=
 body=0A=
 {=0A=
 FONT-SIZE: 10pt;=0A=
 FONT-FAMILY:Tahoma=0A=
 }=0A=
 </style>=0A=
 </head>=0A=
 <body><P>Thanks for the assistance Oliver!</P>
 <P>&nbsp;</P>
 <P>&nbsp;</P>
 <P>But, I have a question, I'm only using IP's and not names, still they lo=
 ok for the DNS?</P>
 <P>&nbsp;</P>
 <P>How can I fix it? My firewall is Freebsd 6 and the Dataserver and most o=
 f Webservers are Windows and one Linux.</P>
 <P>&nbsp;</P>
 <P>Thanks a Lot!!</P>
 <P>&nbsp;</P>
 <P>Best Regards,</P>
 <P>Marcelo<BR><BR></P>
 <P>
 <HR id=3DstopSpelling>
 </P>
 <P>&gt; Date: Sat, 20 May 2006 13:28:29 +0200<BR>&gt; From: olli at lurza.secn=
 etix.de<BR>&gt; To: bug-followup at FreeBSD.org; marcelo_vt at hotmail.com<BR>&gt=
 ; Subject: Re: amd64/97504: IPFW Rules bug<BR>&gt; <BR>&gt; Marcelo&nbsp;Ma=
 chado&nbsp;&lt;marcelo_vt at hotmail.com&gt;&nbsp;wrote:<BR>&gt; &nbsp;&gt;&nb=
 sp;&gt;&nbsp;Number:&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;9=
 7504<BR>&gt; &nbsp;&gt;&nbsp;&gt;&nbsp;Synopsis:&nbsp;&nbsp;&nbsp;&nbsp;&nb=
 sp;&nbsp;&nbsp;IPFW&nbsp;Rules&nbsp;bug<BR>&gt; &nbsp;&gt;&nbsp;&gt;&nbsp;[=
 ...]<BR>&gt; &nbsp;&gt;&nbsp;I've&nbsp;added&nbsp;the&nbsp;following&nbsp;r=
 ules&nbsp;to&nbsp;the&nbsp;ipfw.rules:<BR>&gt; &nbsp;&gt;&nbsp;<BR>&gt; &nb=
 sp;&gt;&nbsp;ipfw&nbsp;add&nbsp;100&nbsp;allow&nbsp;all&nbsp;from&nbsp;192.=
 168.100.3&nbsp;to&nbsp;192.168.100.4<BR>&gt; &nbsp;&gt;&nbsp;ipfw&nbsp;add&=
 nbsp;110&nbsp;allow&nbsp;all&nbsp;from&nbsp;192.168.100.4&nbsp;to&nbsp;192.=
 168.100.3<BR>&gt; &nbsp;&gt;&nbsp;ipfw&nbsp;add&nbsp;65535&nbsp;deny&nbsp;a=
 ll&nbsp;from&nbsp;any&nbsp;to&nbsp;any&nbsp;<BR>&gt; &nbsp;&gt;&nbsp;<BR>&g=
 t; &nbsp;&gt;&nbsp;With&nbsp;these&nbsp;rules&nbsp;the&nbsp;192.168.100.3&n=
 bsp;should&nbsp;ping&nbsp;or&nbsp;interact&nbsp;with<BR>&gt; &nbsp;&gt;&nbs=
 p;192.168.100.4&nbsp;normally,&nbsp;but&nbsp;don't.&nbsp;But&nbsp;if&nbsp;I=
 &nbsp;add&nbsp;this&nbsp;line:<BR>&gt; &nbsp;&gt;&nbsp;<BR>&gt; &nbsp;&gt;&=
 nbsp;ipfw&nbsp;add&nbsp;1&nbsp;allow&nbsp;all&nbsp;from&nbsp;any&nbsp;to&nb=
 sp;any<BR>&gt; &nbsp;&gt;&nbsp;<BR>&gt; &nbsp;&gt;&nbsp;they&nbsp;talk&nbsp=
 ;each&nbsp;other&nbsp;normally,&nbsp;but&nbsp;the&nbsp;most&nbsp;problem&nb=
 sp;comes&nbsp;next,<BR>&gt; &nbsp;&gt;&nbsp;if&nbsp;I:<BR>&gt; &nbsp;&gt;&n=
 bsp;<BR>&gt; &nbsp;&gt;&nbsp;ipfw&nbsp;delete&nbsp;1<BR>&gt; &nbsp;&gt;&nbs=
 p;<BR>&gt; &nbsp;&gt;&nbsp;Everything&nbsp;begins&nbsp;to&nbsp;work&nbsp;as=
 &nbsp;they&nbsp;should,&nbsp;only&nbsp;these&nbsp;IP's&nbsp;can&nbsp;talk<B=
 R>&gt; &nbsp;&gt;&nbsp;with&nbsp;each&nbsp;other&nbsp;on&nbsp;the&nbsp;net.=
 <BR>&gt; <BR>&gt; You&nbsp;probably&nbsp;forgot&nbsp;to&nbsp;allow&nbsp;acc=
 ess&nbsp;to/from&nbsp;your&nbsp;DNS&nbsp;server,<BR>&gt; or&nbsp;something&=
 nbsp;similar.&nbsp;&nbsp;The&nbsp;rule&nbsp;#1&nbsp;will&nbsp;shortly&nbsp;=
 allow&nbsp;that<BR>&gt; access,&nbsp;and&nbsp;when&nbsp;you&nbsp;delete&nbs=
 p;that&nbsp;rule&nbsp;again,&nbsp;it&nbsp;still&nbsp;works<BR>&gt; because&=
 nbsp;the&nbsp;DNS&nbsp;results&nbsp;are&nbsp;cached.<BR>&gt; <BR>&gt; Best&=
 nbsp;regards<BR>&gt; &nbsp;&nbsp;&nbsp;Oliver<BR>&gt; <BR>&gt; --&nbsp;<BR>=
 &gt; Oliver&nbsp;Fromme,&nbsp;&nbsp;secnetix&nbsp;GmbH&nbsp;&amp;&nbsp;Co.&=
 nbsp;KG,&nbsp;Marktplatz&nbsp;29,&nbsp;85567&nbsp;Grafing<BR>&gt; Dienstlei=
 stungen&nbsp;mit&nbsp;Schwerpunkt&nbsp;FreeBSD:&nbsp;http://www.secnetix.de=
 /bsd<BR>&gt; Any&nbsp;opinions&nbsp;expressed&nbsp;in&nbsp;this&nbsp;messag=
 e&nbsp;may&nbsp;be&nbsp;personal&nbsp;to&nbsp;the&nbsp;author<BR>&gt; and&n=
 bsp;may&nbsp;not&nbsp;necessarily&nbsp;reflect&nbsp;the&nbsp;opinions&nbsp;=
 of&nbsp;secnetix&nbsp;in&nbsp;any&nbsp;way.<BR>&gt; <BR>&gt; "I&nbsp;made&n=
 bsp;up&nbsp;the&nbsp;term&nbsp;'object-oriented',&nbsp;and&nbsp;I&nbsp;can&=
 nbsp;tell&nbsp;you<BR>&gt; I&nbsp;didn't&nbsp;have&nbsp;C++&nbsp;in&nbsp;mi=
 nd."<BR>&gt; &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;--&nbsp;Alan&n=
 bsp;Kay,&nbsp;OOPSLA&nbsp;'97<BR></P><br /><hr />MSN Busca: f=E1cil, r=E1pi=
 do, direto ao ponto.  <a href=3D'http://search.msn.com.br' target=3D'_new'>=
 Encontre o que voc=EA quiser. Clique aqui.</a></body>=0A=
 </html>=
 
 --_d6bc2cbb-35e5-41b5-9720-9114e24f7867_--


More information about the freebsd-amd64 mailing list