Is there anything weird I should know about using ipfw on alias addresses?

Ian Smith smithi at nimnet.asn.au
Mon Dec 1 04:51:42 PST 2008


On Mon, 01 Dec 2008 16:52:12 +1300 Brett Davidson <brett at net24.co.nz> wrote:

 > ifconfig shows the alias addresses correctly bound.
 > Creating an ipfw rule and testing it from the command line works 
 > (connects out from master address, not alias)
 > 
 >  From website on alias address, the firewall blocks the packets.
 >
 > The weird thing is that it tags them (in the security log) as coming 
 > from the master address (not the alias) out the correct interface. In a 
 > normal world that would mean the packet would match!!!!!
 > 
 > What's goin' on here Willis?

Difficult to tell without seeing a) ifconfig b) netstat -rn c) at least 
the relevant firewall rule/s and d) log entries that illustrate your 
problem.  Obscure sensitive information by all means, but otherwise 
pretend we haven't the slightest clue how your system is configured :)

cheers, Ian


More information about the freebsd-questions mailing list