|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
From: Crist J. Clark (cristjc
earthlink.net)Date: Mon Oct 01 2001 - 15:25:28 CDT
On Sat, Sep 29, 2001 at 01:31:48AM +0200, Karsten W. Rohrbach wrote:
> stateful rules woud be better, i don't know if this can be done with
> ipfw (but i guess it should work somehow).
There isn't really a good way to do it with dynamic rules in ipfw(8).
> that's the ipfilter config for getting traceroute to work, for those who
> are interested...
>
> # traceroute=30
> pass in quick proto icmp from any to 0.0.0.0/32 icmp-type 30 keep state
> pass out quick proto icmp from 0.0.0.0/32 to any icmp-type 30 keep state
If you actually find a traceroute program that uses the RFC1393
protocol, I'd like to see it.
-- Crist J. Clark cjclarkalum.mit.edu
To Unsubscribe: send mail to majordomo
FreeBSD.org with "unsubscribe freebsd-security" in the body of the message
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]