Re: Complex ruleset questions

This is a discussion on Re: Complex ruleset questions within the IPFilter forums, part of the System Security and Security Related category; Le 2003-06-27, Damian Gerow écrivait : > Was the first way I was doing it. I'm currently breaking ...


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 06-27-2003
Thomas Quinot
 
Posts: n/a
Default Re: Complex ruleset questions

Le 2003-06-27, Damian Gerow écrivait :

> Was the first way I was doing it. I'm currently breaking it down to:
>
> block in log on rl0 from any to any head 10
> block in log on rl0 from any to 192.168.1.1 group 10 head 100
> block in log on rl0 from any to 192.168.1.2 group 10 head 101
> <and others>
>
> block in log on rl1 from any to any head 20
> block in log on rl1 from any to 192.168.1.1 group 20 head 100
> block in log on rl1 from any to 192.168.1.2 group 20 head 101
> <and others>


Does this work? ipfilter is not supposed to support multiple heads for
the same group, AFAIK.

> block in log on {rl0,rl1} from any to any head 20
> <service-specific forwards here>


skip 2 in on rl0 from any to any
skip 1 in on rl1 from any to any
skip 1 in from any to any
block in log from any to any head 20

Thomas.

--
Thomas.Quinot@Cuivre.FR.EU.ORG
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 05:27 PM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0