Re: Problems with icmp and ipfilter.

This is a discussion on Re: Problems with icmp and ipfilter. within the IPFilter forums, part of the System Security and Security Related category; Scott Walker wrote: > block in proto icmp all > pass in quick on fxp0 proto icmp from any to ...


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 05-11-2006
michael.lim
 
Posts: n/a
Default Re: Problems with icmp and ipfilter.

Scott Walker wrote:

> block in proto icmp all
> pass in quick on fxp0 proto icmp from any to any icmp-type echo
> pass in quick on fxp0 proto icmp from any to any icmp-type echorep
> pass in quick on xl0 proto icmp from any to any icmp-type echo
> pass in quick on xl0 proto icmp from any to any icmp-type echorep
> pass in quick on tun0 proto icmp from any to any icmp-type echo
> pass in quick on tun0 proto icmp from any to any icmp-type echorep
>
> Should the above rules allow me to ping across networks? The FW itself
> can ping all the hosts on both sides, but for example hosts strung off
> the tun0 VPN tunnel can't ping the FW, hosts on xl0 (internal lan) can't
> ping the FW or hosts on the VPN.
>
> Am I missing something? This seems pretty simple to do.


do the tunneled packets appear as ICMP or raw IP?

what is the output of ipfstat -hio?

-Mike
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 10:47 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0