Running Dummynet

wmoran at compunetix.com wmoran at compunetix.com
Tue May 27 03:53:27 PDT 2003


> Bill Moran wrote:
>> Fehmi wrote:
>>
>>> ipfw show:
>>> 100 allow ip from any to any
>>> 200 pipe 1 bw 1kbit/s delay 200ms
>>> 65554 deny ip from any to any
>>
>>
>> This actually works?  It looks to me like everything should be
>> blocked by the last rule: thus no networking should work.
>
> I have to disagree. Everything will be *allowed* by the *first* rule,
> none of the other rules will ever happen, including the last one.
> This is pretty much as effective as no firewall at all.

Agreed.  I must have been asleep at the wheel when I looked at it.
And you've also described the problem to the orignal poster.


More information about the freebsd-questions mailing list