*BSD News Article 41858


Return to BSD News archive

Xref: sserve comp.os.386bsd.questions:16326 comp.os.386bsd.misc:5156
Path: sserve!newshost.anu.edu.au!munnari.oz.au!bruce.cs.monash.edu.au!harbinger.cc.monash.edu.au!newshost.marcam.com!news.mathworks.com!news.alpha.net!usenet
From: Dick@Seaman.Chenequa.WI.US   (Richard Seaman, Jr.)
Newsgroups: comp.os.386bsd.questions,comp.os.386bsd.misc
Subject: Re: FreeBSD 2.0: ipfirewall kernl config
Date: 27 Jan 1995 15:30:12 GMT
Organization: Alpha.net -- Milwaukee, WI
Lines: 29
Message-ID: <3gb3i4$4d6@homer.alpha.net>
References: <3gaudh$1k@clarknet.clark.net>
Reply-To: Dick@Seaman.Chenequa.WI.US(Richard Seaman, Jr.)
NNTP-Posting-Host: spro.seaman.quaestus.com
X-Newsreader: IBM NewsReader/2 v1.03

In <3gaudh$1k@clarknet.clark.net>, rwatson@clark.net (Robert Watson) writes:
>The two information example files mentioned in the manpage for ipfw did 
>not come with our distribution (/usr/share/misc/ipfw.sampe.*) -- we're 
>trying to configure our firewall using FreeBSD's ipfirewall kernel 
>routines, and some information in the ipfw command's incantations and 
>functions would really be helpful ;).  Also as to what settings we have 
>to include in the kernel (other than the options IPFIREWALL).  
>
>Thanks...
>
>Robert Watson
>rwatson@clark.net, rwatson@confused.student.sidwell.edu
>
>

I don't have what you're looking for.  But, I'm under the impression that the
man pages for ipfw are not accurate, at least for the post 2.0R current and
latest snapshot.  I think the addb and delb commands no longer exist and
there is a "v" or "via" command, so you could say:

ipfw addf accept tcp from 0 telnet,ftp to <localaddr:localmask> via <ext. interface IP>

I also believe you need the options GATEWAY command in your config file.


Richard Seaman, Jr.         Dick@Seaman.Chenequa.WI.US
5182 North Maple Lane       voice: 414-367-5450
Chenequa, WI 53058          fax:   414-367-5852