Re: ipf stopped working on 5.3

ray_at_redshift.com
Date: 10/27/05

  • Next message: jimmy_at_inet-solutions.be: "Re: Non-executable stack"
    Date: Wed, 26 Oct 2005 23:17:19 -0700
    To: John Fitzgerald <jjfitzgerald@gmail.com>
    
    

    At 01:12 PM 10/26/2005 -0400, John Fitzgerald wrote:
    | Another strange symptom is that if I ipf -D and then ipf -E -f
    | /etc/ipf.rules, my terminal (I'm remote) will freeze and I'll be forced to
    | power cycle the server, after which time it will come back up (with no rules
    | running). I'm assuming that after the ipf -E -f /etc/ipf.rules somehow the
    | firewall stops all traffic since apache won't respond to web requests
    | either.
    |
    | As a side note, I did put the sshd server listening on an obscure port so it
    | should take awhile for the bots to find it. The ipf.rules I left at 22 as a
    | testament to it not working. However this obviously isn't a permanent
    | solution as I should be able to get ipf working.

    after you make changes to ipf.rules, you should restart ipf like this:

    ipf -F a && ipf -f /etc/ipf.rules

    -F will flush your old rules, whereas ipf -D will disable ipf. Try the line
    above and see if your SSH session remains active after you make changes, etc.

    Ray

    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: jimmy_at_inet-solutions.be: "Re: Non-executable stack"

    Relevant Pages

    • udp fragmentation with pf/ipf
      ... we discovered a possible problem with ipf and pf in FreeBSD ... ; (1 server found) ... ;; global options: printcmd ... pass out on bge0 proto tcp all keep state ...
      (freebsd-net)
    • udp fragmentation with pf/ipf
      ... we discovered a possible problem with ipf and pf in FreeBSD ... ; (1 server found) ... ;; global options: printcmd ... pass out on bge0 proto tcp all keep state ...
      (freebsd-stable)
    • Re: IP range to CIDR list VB6 utility?
      ... That's why I run 2 software based firewalls on the server itself: ... I found that ZAP was better (actually, ... of course IIS uses URLScan to also detect attack signatures (and this is ... dynamically modify and then reload the IPF rules in response to an attack. ...
      (microsoft.public.vb.general.discussion)
    • Re: IP range to CIDR list VB6 utility?
      ... your system does or how your IPF is setup... ... >no IP addresses) statefull firewall FreeBSD box dedicated to running only ... >require using CIDR instead of ranges. ... >reduce and to eventually remove the firewall load on the server box. ...
      (microsoft.public.vb.general.discussion)
    • Re: IP range to CIDR list VB6 utility?
      ... >no IP addresses) statefull firewall FreeBSD box dedicated to running only ... >one thing, a firewall called IP Filter (aka IPF), and its filter rules ... >require using CIDR instead of ranges. ... >reduce and to eventually remove the firewall load on the server box. ...
      (microsoft.public.vb.general.discussion)