ipf & icmp pakety - kde je problem ?

Brano Vislocky brano at zmail.sk
Wed Jul 17 16:05:42 CEST 2002


Ahojte,

povedzme, ze karta ep1 (vonkajsia) ma ip 1.2.3.4

a pravidla pre ipf su taketo:

block  in log on ep1 all head 1
pass in quick on ep1 proto icmp from any to 1.2.3.4/32 icmp-type 0 group 1
pass in quick on ep1 proto icmp from any to 1.2.3.4/32 icmp-type 11 group 1


predpokladam, ze 1. riadok je 'default' pravidlo pre group 1

no a problem je ten, ze ked ping-ujem kartu ep1, tak sa mi v logoch 
objavi take nieco:

ipmon: 15:05:40.992524 ep1 @0:6 b x.x.x.x -> 1.2.3.4 PR icmp len 20 84 
icmp echo/0 IN

t.j. ze mi dropne paket podla 'default' pravidla pre skupinu.

preco ?  co je na tom nespravne ?

dakujem

Brano.




More information about the Users-l mailing list