Just trying to enable SSH in IPFW. Been trying for ages.
Please help me, what's going wrong??
EDIT: I found out a problem is here.
But new set of rules still not working?
New:
Old:
My
Please help me, what's going wrong??
Code:
ipfw disable firewall
$ ssh freebsd@192.168.1.95
Password for freebsd@mac1b:
Last login: Sat Aug 1 14:46:38 2015
.....
ipfw enable firewall
debian@l1d:~$ ssh freebsd@192.168.1.95
[I][B]ssh: connect to host 192.168.1.95 port 22: Connection timed out[/B][/I]
EDIT: I found out a problem is here.
Code:
00700 deny tcp from any to any
But new set of rules still not working?
New:
Code:
00100 allow ip from any to any via tun0
00200 allow ip from any to any via tap0
00300 allow udp from any to 10.1.2.0 dst-port 22222 setup
00400 allow udp from any to any via em0
00500 allow tcp from any to me
00600 allow tcp from any to any dst-port 22
00700 allow tcp from any to me dst-port 22
00800 allow tcp from any to any dst-port 22 in
00900 allow tcp from any to me
01000 allow tcp from any to me dst-port 22 keep-state
01100 allow tcp from any to me via em0
01200 allow tcp from any to any dst-port 22 out
65535 deny ip from any to any
Old:
Code:
00100 allow ip from any to any via tun0
00200 allow ip from any to any via tap0
00300 allow udp from any to 10.1.2.0 dst-port 22222 setup
00400 allow udp from any to any via em0
00500 allow tcp from any to me via tun0
00600 allow tcp from any to any established
00700 deny tcp from any to any
00800 allow tcp from any to any dst-port 22
00900 allow tcp from any to any dst-port 22 in
01000 allow tcp from any to any dst-port 22 out
01100 allow tcp from any to me dst-port 22 keep-state
65535 deny ip from any to any
My
ifconfig
Code:
em0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500
options=9b<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,VLAN_HWCSUM>
ether 08:00:27:89:20:db
inet 192.168.1.95 netmask 0xffffff00 broadcast 192.168.1.255
nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
media: Ethernet autoselect (1000baseT <full-duplex>)
status: active
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384
options=600003<RXCSUM,TXCSUM,RXCSUM_IPV6,TXCSUM_IPV6>
inet6 ::1 prefixlen 128
inet6 fe80::1%lo0 prefixlen 64 scopeid 0x2
inet 127.0.0.1 netmask 0xff000000
nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
groups: lo
tun0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> metric 0 mtu 1500
options=80000<LINKSTATE>
inet6 fe80::a00:27ff:fe89:20db%tun0 prefixlen 64 scopeid 0x3
inet 10.1.2.1 --> 10.1.2.2 netmask 0xffffff00
nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
groups: tun
Opened by PID 618