Configuring IPFW

Carmel carmel_ny at
Sat Oct 22 13:56:16 UTC 2011

I am attempting to set up a firewall using IPFW with a stateful

While I have investigated how to set up these rules, I have run into
conflicting opinions as to whether to all or deny "established"

EXAMPLE: (preceded by a "checkstate" rule)

allow tcp from any to any established

Some documentation states that it should be denied and others say it
should be allowed. Neither has given me a convincing reason to follow
either scenario or any real documentation either for that fact.

If possible, could someone with some real firewall knowledge and
familiarity with IPFW please give me some advice.


Carmel ✌
