Problem with passive ftp in IPFW!

Michael Sierchio kudzu at tenebras.com
Mon Jan 16 20:09:47 UTC 2012


On Mon, Jan 16, 2012 at 11:05 AM, Freddie Cash <fjwcash at gmail.com> wrote:

> Personally, I don't use skipto rules, as I find them to just cause
> confusion. ...

skipto rules are essential in numerous instances, especially once you
start using tableargs, or want to partition your ruleset based on
incoming interface.

> Personally, I also don't use stateful filter rules ...

Perhaps not, but they're useful for outbound connections/dns queries/etc.


More information about the freebsd-ipfw mailing list