nameserver - block some sites

starikarp at dismail.de starikarp at dismail.de
Sat Jun 8 10:35:11 UTC 2019


Hi!

I am using default settings for ipfw-workstation on my FreeBSD-12.0
Release.
Mine nameserver is dns.watch and I have a problem because firewal block
me some sites:
kernel: ipfw: 65500 Deny UDP 84.200.69.80:53 192.168.1.2:32998 in via
bge0

Bellow is part of reassemble from the rc.firewall and my question is if
is correct order - I read somewhere tha "check-state" should be after
"reass".

 # Allow packets for which a state has been built. ${fwcmd} add
check-state # reassemble incoming fragmented packets
        ${fwcmd} add reass all from any to any in

Is there any option to resolve my problem with blocking some sites,
please?

Thank you.
-- 
by ajtiM
----------------------
FreeBSD 12.0-Release


More information about the freebsd-ipfw mailing list