Configuring IPFW
RW
rwmaillists at googlemail.com
Sat Oct 22 16:55:04 UTC 2011
On Sat, 22 Oct 2011 09:56:12 -0400
Carmel wrote:
> I am attempting to set up a firewall using IPFW with a stateful
> behavior.
>
> While I have investigated how to set up these rules, I have run into
> conflicting opinions as to whether to all or deny "established"
> behavior.
>
> EXAMPLE: (preceded by a "checkstate" rule)
>
> allow tcp from any to any established
>
>
> Some documentation states that it should be denied and others say it
> should be allowed. Neither has given me a convincing reason to follow
> either scenario or any real documentation either for that fact.
Normally if the rules are stateless you would allow established tcp
packets, but would deny them with stateful rules. In the latter case,
established traffic would be passed by the check-state
More information about the freebsd-questions
mailing list