OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: ipf question

From: Erick Mechler (emechlertechometer.net)
Date: Wed Jan 19 2005 - 12:01:31 CST


:: pass in quick on xl0 proto tcp/udp from any to any port 137 <> 139 keep
:: state

This line allows in all tcp and udp ports less than 137 and greater than
139, which is exactly what you don't want :) If you want to allow all
ports 137-139 inclusive, you need to change it to

  ... port 136 >< 140 keep state

The < and > operators are not inclusive.

Cheers - Erick
_______________________________________________
freebsd-securityfreebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribefreebsd.org"