Re: [fw-wiz] IPFW on OS X issues

From: Barney Wolff (barney_at_databus.com)
Date: 07/28/03

  • Next message: Don Kendrick: "RE: [fw-wiz] Off topic: Any one know of a good IPV6 reference book?"
    To: Rishi Pande <rpande@vt.edu>
    Date: Mon, 28 Jul 2003 16:45:27 -0400
    
    

    On Mon, Jul 28, 2003 at 08:07:40PM -0000, Rishi Pande wrote:
    > I am having problems with an OS X machine on which I set up
    > an IPFW firewall. The firewall does not allow SLP network browsing
    > on port 427. I log all the denied entries and the log shows about
    > 10 messages a second of more or less the same message. Here's
    > a sampling of the log:
    >
    > Jul 28 15:44:13 nom mach_kernel: ipfw: 7000 Deny UDP
    > 128.173.125.180:49807 239.255.255.253:427 in via en0
    > Jul 28 15:44:13 nom mach_kernel: ipfw: 7000 Deny UDP
    > 128.173.201.44:49406 239.255.255.253:427 in via en0
    >
    > The funny part is my machine is not 239.255.255.253. I have
    > installed the same firewall on different machines but they don't
    > seem to have any such problems.

    239.255.255.253 is a multicast address. 7000 is the rule number
    that's blocking the packets. ipfw rules are evaluated in order.
    Knowing that, look at your rules.

    -- 
    Barney Wolff         http://www.databus.com/bwresume.pdf
    I'm available by contract or FT, in the NYC metro area or via the 'Net.
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: Don Kendrick: "RE: [fw-wiz] Off topic: Any one know of a good IPV6 reference book?"

    Relevant Pages

    • Re: OT:Port Security test
      ... > I am behind a nat router and i have a software firewall. ... the same port list as yours, ... otherwise I'd have had a lot of denied entries in my PIX log (everything is ...
      (uk.media.dvd)
    • Re: Leopard Firewall Warning
      ... The old port-based firewall, ... You can't control *which* ports a particular app is allowed to use. ... keep switching the ipfw firewall off if you do certain things, ...
      (uk.comp.sys.mac)
    • Re: OT:Port Security test
      ... >> I am behind a nat router and i have a software firewall. ... > the same port list as yours, ... > the network, both from inside and outside the firewall, using nmap and a ... > otherwise I'd have had a lot of denied entries in my PIX log (everything ...
      (uk.media.dvd)
    • [fw-wiz] IPFW on OS X issues
      ... an IPFW firewall. ... The firewall does not allow SLP network browsing ... 128.173.201.44:49406 239.255.255.253:427 in via en0 ... Needless to say all the machines time is spent writing to the log ...
      (Firewall-Wizards)
    • Re: Leopard Firewall Warning
      ... The old port-based firewall, ... When you enable an application to access the network, Apple signs the ... because Leopard will ... keep switching the ipfw firewall off if you do certain things, ...
      (uk.comp.sys.mac)