Re: [fw-wiz] IPFW on OS X issues

From: Chuck Swiger (chuck_at_codefab.com)
Date: 07/28/03

  • Next message: Barney Wolff: "Re: [fw-wiz] IPFW on OS X issues"
    To: Rishi Pande <rpande@vt.edu>
    Date: Mon, 28 Jul 2003 16:45:07 -0400
    
    

    Rishi Pande wrote:
    [ ... ]
    > Jul 28 15:44:13 nom mach_kernel: ipfw: 7000 Deny UDP
    > 128.173.125.180:49807 239.255.255.253:427 in via en0
    > Jul 28 15:44:13 nom mach_kernel: ipfw: 7000 Deny UDP
    > 128.173.201.44:49406 239.255.255.253:427 in via en0
    >
    > The funny part is my machine is not 239.255.255.253. I have
    > installed the same firewall on different machines but they don't
    > seem to have any such problems.

    OK; how do you want to handle this traffic? You could continue to block SLP and
    not log these messages by removing the log keyword from the 7000 ruleset.

    You could also do something like:

    ipfw add 6999 pass udp from any to any 427

    ...on the hosts on your network; presumably, you would have a tighter ruleset on
    your Internet-bound firewall.

    -- 
    -Chuck
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: Barney Wolff: "Re: [fw-wiz] IPFW on OS X issues"

    Relevant Pages

    • Re: My customers keep getting infected?
      ... > application was giving them trouble and a guru suggested it was a firewall ... Now that's actually funny - disable the protection method, ...
      (alt.computer.security)
    • Re: Patcher...
      ... I found this morning that it will not work at all if my firewall is ... Funny, I thought it worked better this time. ... like corkscrews. ... Prev by Date: ...
      (alt.games.warcraft)
    • Re: Smoothwall website hacked
      ... > Although it is indeed very funny and ironic, it was the webserver that ... > got hacked not the firewall. ... taking a system offline (say booting off a Knoppix CD and mounting the ...
      (comp.os.linux.security)
    • SMTP mail inbound are rejected
      ... I have installed Exchange 2003 behind a firewall. ... I cannot receive mail from the Internet, ... The funny thing is that when I use telnet on the local ...
      (microsoft.public.exchange.setup)