Re: IPFILTER_DEFAULT_BLOCK & No route to host

From: Dag-Erling Smørgrav (des_at_des.no)
Date: 09/30/03

  • Next message: Justin: "Re: IPFILTER_DEFAULT_BLOCK & No route to host"
    To: echelon <e_chelon@yahoo.com>
    Date: Tue, 30 Sep 2003 16:54:40 +0200
    
    

    echelon <e_chelon@yahoo.com> writes:
    > However, I use the following rules for the internal network interface (xl1)
    >
    > # Group 9000 (internal network interface)
    > block return-rst in log quick on xl1 proto tcp from any to 192.168.x.x/32 port = 23 group 9000
    > block return-rst in log quick on xl1 proto tcp from any to 192.168.x.x/32 port = 21 group 9000
    > pass in quick on xl1 all group 9000
    >
    > With these rules, I believe I should able to ping and SSH the
    > freebsd box from my internal network no matter the option
    > IPFILTER_DEFAULT_BLOCK is set or not.

    You're only letting traffic *in*. You're not letting anything *out*.
    TCP, like love, is a two-way street.

    DES

    -- 
    Dag-Erling Smørgrav - des@des.no
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Justin: "Re: IPFILTER_DEFAULT_BLOCK & No route to host"

    Relevant Pages

    • Re: IPFILTER_DEFAULT_BLOCK & No route to host
      ... I use the following rules for the internal network interface (xl1) ... I believe I should able to ping and SSH the ...
      (freebsd-stable)
    • Re: Redhat 9 and IP Masquerading
      ... eth1 connected to internal network via switch. ... From the Redhat machine I can not ping any host on the internal network ... > from internal hosts or just from the RH9 box? ...
      (RedHat)
    • Re: Browsing Web Pages
      ... I can't reach the site with the command ping, and I get this with a tracert: ... When I saw that I could resolve his DNS into the internal network, ...
      (microsoft.public.windows.server.dns)
    • Re: Redhat 9 and IP Masquerading
      ... from internal hosts or just from the RH9 box? ... on the internal network I can not see nor ping any host. ... I can't ping anything. ... have you turned on ip forwarding on your RH9 box? ...
      (RedHat)
    • Re: Cant use internal network after dialup modem is used -- FOLLOWUP: better output
      ... Here is a corrected/improved version with more useful indenting. ... Just after reboot, can use internal network. ... In particular, during and after use of dialup modem, ping gives: ... packets transmitted, 4 packets received, 0% packet loss ...
      (comp.os.linux.setup)