OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Krzysztof Zaraska (kzaraskastudent.uci.agh.edu.pl)
Date: Fri Apr 05 2002 - 04:59:44 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    On Fri, 05 Apr 2002 07:44:45 -0000 ozkan_kirik wrote:

    > after i built my kernel, i couldnt ping to anywhere even router, & i
    > couldnt ping to my firewall.

    I don't quite understand you... Usually the firewall should be setup the
    way allowing you to ping outside host, but the external world should not
    be able to ping you.
     
    > what the problem can be?
    >
    > the options on kernel are:
    >
    > IPFIREWALL
    > IPDIVERT
    > IPFIREWALL_FORWARD
    > IPFIREWALL_VERBOSE
    > IPFIREWALL_VERBOSE_LIMIT=100
    > IPFIREWALL_DEFAULT_TO_ACCEPT
    ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

    This will let through any traffic not explicitely denied.

    Standard recommended setup is 'default to deny'.

    > IPFILTER
    > IPFILTER_LOG

    Are you sure you want to run both ipf and ipfw at the same time?

    -- 
    // Krzysztof Zaraska * kzaraska (at) student.uci.agh.edu.pl
    // Prelude IDS: http://www.prelude-ids.org/
    // A dream will always triumph over reality, once it is given the chance.
    //		-- Stanislaw Lem
    

    To Unsubscribe: send mail to majordomoFreeBSD.org with "unsubscribe freebsd-security" in the body of the message