ipf & icmp pakety - kde je problem ?

Milos Urbanek urbanek at openbsd.cz
Thu Jul 18 14:29:15 CEST 2002


On Wed, Jul 17, 2002 at 04:16:44PM +0200, Juraj Lutter wrote:
> On Wed, Jul 17, 2002 at 04:05:42PM +0200, Brano Vislocky wrote:
> > Ahojte,
> > block  in log on ep1 all head 1
> > pass in quick on ep1 proto icmp from any to 1.2.3.4/32 icmp-type 0 group 1
> > pass in quick on ep1 proto icmp from any to 1.2.3.4/32 icmp-type 11 group 1
> > 
> > 
> > predpokladam, ze 1. riadok je 'default' pravidlo pre group 1
> > 
> > no a problem je ten, ze ked ping-ujem kartu ep1, tak sa mi v logoch 
> > objavi take nieco:
> > 
> > ipmon: 15:05:40.992524 ep1 @0:6 b x.x.x.x -> 1.2.3.4 PR icmp len 20 84 
> > icmp echo/0 IN

co takhle zmenit
icmp-type 0 na icmp-type 8  a pridat keep state?

#define ICMP_ECHO               8               /* echo service */
#define ICMP_ECHOREPLY          0               /* echo reply */


Milos



More information about the Users-l mailing list