Re: insight on S10 ipfilter patch 125014-02?

This is a discussion on Re: insight on S10 ipfilter patch 125014-02? within the IPFilter forums, part of the System Security and Security Related category; Jeff A. Earickson wrote: > On Tue, 6 Mar 2007, Darren Reed wrote: > >> Date: Tue, 06 Mar ...


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 03-09-2007
Darren Reed
 
Posts: n/a
Default Re: insight on S10 ipfilter patch 125014-02?

Jeff A. Earickson wrote:
> On Tue, 6 Mar 2007, Darren Reed wrote:
>
>> Date: Tue, 06 Mar 2007 11:43:32 -0800
>> From: Darren Reed <darrenr@reed.wattle.id.au>
>> To: Jeff A. Earickson <jaearick@colby.edu>
>> Cc: Carson Gaspar <carson@taltos.org>, ipfilter@coombs.anu.edu.au
>> Subject: Re: insight on S10 ipfilter patch 125014-02?
>>
>> Jeff A. Earickson wrote:
>>> ...

>>
>> It is IPMP and "keep state".
>> Unless you use ndd to define an IPMP interface group there, it
>> is not possible to use stateful filtering as "keep state" tries to bind
>> the connection to specific NICs but IPMP sends them out over
>> either one.
>>
>> You could also try this:
>>
>> pass in quick on -,- out-via -,- proto tcp from any to any port = 25
>> flags S keep state
>> pass out quick on -,- out-via -,- proto tcp from any to any port = 25
>> flags S keep state

>
> Darren,
>
> What goes in the "-,-" spots? MAC,port? Is the "out-via" keyword
> supported in ipfilter 4.1.9 (aka, Sun patch 125014-02)? Sun version
> 4.0.3? Or only in later public-domain releases?


It should be in both.
The rules above are literal text - using "-" as the interface name.
Except for one bug (see previous patch)..


> ...
> Then if I want to use "keep state" rules with this configuration, I have
> to set the value of qif_ipmp_set for pfil via ndd:
>
> ndd -set /dev/pfil qif_ipmp_set ipmp0=ce0,ce1
>
> Correct? Is that it? Then just write an init script to preserve the ndd
> setting across reboots? Without the "ndd -set" my usage of IPMP and
> "keep state" rules is doomed to failure?


yes, yes yes, yes :)

I need to provide a place to do it in the pfil startup script.

Darren

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 07:28 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0