1. FKEinternet

    Solved ipfw vs. ping puzzle

    My servers Dreamer and Wren each have two interfaces, connected to two routers. The re0 interfaces are connected to the 192.168.14.* subnet, and the re1 interfaces are connected to the 192.168.1.* subnet. The 192.168.1.* subnet originates at a Verizon router, which is also upstream from an...
  2. dave

    IPFW Simple IPFW Setup From Handbook Locks Me Out

    Hello, /etc/rc.conf firewall_enable="YES" firewall_type="open" ...followed by... sudo service ipfw start ...results in immediate loss of all connectivity. Am I missing something? FreeBSD 10.2-RELEASE-p7
  3. J

    IPFW Ordering of ipfw rules and sets

    Hi, this is a question about the ordering of ipfw rules. As stated in the documentation ( https://www.freebsd.org/doc/handbook/firewalls-ipfw.html ), the ipfw command syntax is: CMD RULE_NUMBER set SET_NUMBER ACTION log LOG_AMOUNT PROTO from SRC SRC_PORT to DST DST_PORT OPTIONS Does the...
  4. J

    IPFW ipfw stateful ftp?

    Hi everyone, I'm new to this forum and I got into FreeBSD only a few weeks ago (I used Linux before that). I'm trying to set up a minimal firewall configuration for a remote computer. Here is the script in my /etc/ipfw.rules file. #!/usr/bin/env bash nic=`netstat -r | awk '/^default/ {print...
  5. A

    IPFW natd to ipfw nat

    Hello there, I just deployed simple private OpenVPN service by following instructions from: https://www.digitalocean.com/community/tutorials/how-to-configure-and-connect-to-a-private-openvpn-server-on-freebsd-10-1 Well, everything seems to be fine ... except I observed that 'natd' process...
  6. xoptov

    Solved ipfw0: That device doesn't support promiscuous mode

    Hello! I have very strange issue with ipfw0. My kernel has options IPFIREWALL and IPFIREWALL_VERBOSE but when I try listen ipfw0 interface see warning in my console: tcpdump: WARNING: ipfw0: That device doesn't support promiscuous mode (BIOCPROMISC: Invalid argument) What is I can fix for...
  7. AlexUnix

    IPFW IPFW Kernel NAT is not working

    Please help. I have version 10.2-RELEASE with kernel NAT configured. Ping request pass to external adapter, but don't route back to internal. Internal (ue1): # tcpdump -ni ue1 | grep tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on ue1...
  8. B

    Solved Basic firewall config for a host

    Hello, everyone, and nice to meet you! I am new to FreeBSD (so fresh that I'm downloading the ISO as I write, that means I've never used FreeBSD before). I come from the Linux world and one of the first things I do when I install a distro, before going to update and configure it, is to set up...