IPFW equivalent of iptables --state ESTABLISHED, RELATED

Chuck Swiger cswiger at mac.com
Sun Oct 23 08:37:03 PDT 2005


John Do wrote:

> Hi guys
> 
> I'm having trouble with IPFW I need to allow user
> initiated traffic IN but I can't
> 
> Basically in iptables for Linux I would have used
> something like
> -A INPUT -p tcp -m tcp --state ESTABLISHED,RELATED -j
> ACCEPT
> 
> 
> Can someone help me discover what the equivalent
> syntax in IPFW would be?
> 
> I have tried to use "allow tcp from any to any
> established in" but it doesn't work 

"allow tcp from any to any established"

...as another poster said, however, this will allow data traffic not associated 
with legitimate connections in, too.  If you want use stateful rules in IPFW, 
something like:

check-state
allow ip from me to any setup keep-state

Take a look at /etc/rc.firewall for more detailed rules...

-- 
-Chuck



More information about the freebsd-questions mailing list