firewalling with tunnels, and/or ipv6

Brooks Davis brooks at one-eyed-alien.net
Mon Dec 20 21:55:27 PST 2004


On Mon, Dec 20, 2004 at 06:05:16PM -0800, Charlie Schluting wrote:
> Ok, I've got a v6 tunnel, and to make it work I had to "allow ipv6 from 
> <endpoint>" in ipfw. From what I understand, I have to make a completely 
> different set of rules for ipv6, and load them using the -6 flag.
> 
> Correct so far?

ip6fw is an entierly different beast from ipfw.  There is no -6 option
to ipfw.  Use ip6fw instead.  If 6.x we should have ipv6 support in ipfw
and ip6fw should be gone.

-- Brooks

-- 
Any statement of the form "X is the one, true Y" is FALSE.
PGP fingerprint 655D 519C 26A7 82E7 2529  9BF0 5D8E 8BE9 F238 1AD4
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: not available
Url : http://lists.freebsd.org/pipermail/freebsd-net/attachments/20041220/71c93f3f/attachment.bin


More information about the freebsd-net mailing list