Configuring IPFW

Carmel carmel_ny at hotmail.com
Sat Oct 22 13:56:16 UTC 2011


I am attempting to set up a firewall using IPFW with a stateful
behavior.

While I have investigated how to set up these rules, I have run into
conflicting opinions as to whether to all or deny "established"
behavior.

EXAMPLE: (preceded by a "checkstate" rule)

allow tcp from any to any established


Some documentation states that it should be denied and others say it
should be allowed. Neither has given me a convincing reason to follow
either scenario or any real documentation either for that fact.

If possible, could someone with some real firewall knowledge and
familiarity with IPFW please give me some advice.

Thanks!

-- 
Carmel ✌
carmel_ny at hotmail.com



More information about the freebsd-questions mailing list