IPFW2 tables
NetAdmin
daemon at foxchat.net
Wed Nov 24 00:27:16 GMT 2004
On Tue, 2004-11-23 at 22:29 +0000, Thomas Wolf wrote:
> NetAdmin <daemon at foxchat.net> schrieb:
>
>
> > > > Set rule as; *Note: found there was a problem using table (1)
> > > > {fwcmd} add 300 deny ip from table '1' to me
> > >
> > > The correct syntax that should work under any shell should be
> > > {fwcmd} add 300 deny ip from table\(1\) to me
> > > or
> > > {fwcmd} add 300 deny ip from "table(1)" to me
> > >
> > >
> >
> > Great! That worked. Thanks. Now, is there a page I can refer to for
> > other commands and syntax like adding multiple ports?
>
> 'man 8 ipfw' is still the best reference for commands and syntax (IMHO).
>
>
> > I tried the
> > following and assume it works.
> >
> > ${fwcmd} add 301 deny all from "table(2)" to me 20-25,110,113,143
> >
> > # ipfw show
> > 00301 0 0 deny ip from table(2) to me dst-port
> > 20-25,110,113,143
>
> That looks ok. Although I would 'unreach host' or 'reset' packets
> to ident (port 113). 'Dropping' them just gets you delays when
> querying mailservers and other services.
>
> Thomas
I did look at the man page for tables. The only thing really mentioned
is;
ipfw table number add addr[/masklen] [value]
ipfw table number delete addr[/masklen]
ipfw table number flush
ipfw table number list
and
LOOKUP TABLES
Lookup tables are useful to handle large sparse address sets,
typically
from a hundred to several thousands of entries. There could be 128
dif-
ferent lookup tables, numbered 0 to 127. etc... etc...
Make no mistake, I appreciate your help immensely and unless someone
else had responded, I would still be wondering what I needed to do.
However, I have checked the sources commonly available to newer users
including searches on google. Having said that, no where in 'man 8
ipfw' does it say how to add multiple ports in conjunction with Tables
or the correct syntax for adding the table to rc.firewall. Tables for
IPFW isn't even mentioned in
http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/firewalls.html
That is why I asked if anyone knew of any other sources of information
on Tables and their syntax. It is what I am still asking. Where can I
find more information on using tables with IPFW?
Respectfully,
Mark
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 187 bytes
Desc: This is a digitally signed message part
Url : http://lists.freebsd.org/pipermail/freebsd-ipfw/attachments/20041123/70c189c6/attachment.bin
More information about the freebsd-ipfw
mailing list