Re: IPFW disconnections and resets

From: Siddhartha Jain (sid_at_netmagicsolutions.com)
Date: 04/29/05

  • Next message: Andrew McNaughton: "Re: IPFW disconnections and resets"
    Date: Fri, 29 Apr 2005 17:50:59 +0530
    To: freebsd-security@freebsd.org
    
    

    Michael Scheidell wrote:
    >>I use that all the time, maybe 1 out of 100 times it will kill
    >>a ssh session (only one that has irssi open cause of the time
    >>updating it kills it, i have it set to update every second
    >>though, so normally it'd be like 1 out of 500 or so) and even
    >>if it does, it still finishes loading the ruleset anyway so
    >>you can just ssh straight back in
    >
    >
    > I used
    >
    > sysctl -a net.inet.ip.fw.enable=0 && firewall.sh &&
    > net.inet.ip.fw.enable=1 && sleep 60 && reboot
    > and I would hit a ^c to stop the sleep and reboot if I didn't wack the
    > firewall rules.
    > The reboot would put it back to rc.conf firewall
    >
    > Never got disconnected.
    >

    Just out of curiosity, why is that IPFW behaves this way and PF and IPF
    don't?

    - Siddhartha

    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Andrew McNaughton: "Re: IPFW disconnections and resets"

    Relevant Pages

    • RE: IPFW disconnections and resets
      ... > a ssh session (only one that has irssi open cause of the time ... The reboot would put it back to rc.conf firewall ... Only window of vulnerability was while loading new firewall rules. ...
      (FreeBSD-Security)
    • Re: [opensuse] SSH session not terminated when rebooting machine + startup question
      ... ssh session is not terminated in any case - I can submit ... reboot from other session or locally, ... doing a "ps afx" shows that the sshd daemon did not die: ... shutdown rather that to startup though. ...
      (SuSE)
    • Re: SSH question
      ... AIUI the task survives the loss of the ssh session, what kills it is the next time it tries to print something it gets a nasty signal along the lines of "don't know what you think you are printing to, but it isn't there any more". ...
      (Fedora)
    • NATD remote management
      ... I manage a remote gateway/nat/router/fw server where it is not convenient ... for anyone to go downtown to the colo and do reboots. ... reboot and it comes up okay, but rather would avoid a reboot. ... Obviously, when I do the kill of natd, it disconnects my SSH session and I ...
      (freebsd-questions)
    • NATD config remote management
      ... I manage a remote gateway/nat/router/fw server where it is not convenient ... for anyone to go downtown to the colo and do reboots. ... reboot and it comes up okay, but rather would avoid a reboot. ... Obviously, when I do the kill of natd, it disconnects my SSH session and I ...
      (freebsd-questions)