improve ipfw rules

Richy Kim rkim at sandvine.com
Tue Feb 24 07:09:27 PST 2004


>> 3. I'm intrested in blocking kazaa/P2P trafic with IPFW any help in this
issue
you could possibly block connections at known p2p ports.
deny tcp from any to any 6699 step
but most of the newer protocols use dynamic ports and in turn, are
configurable. 
so ipfw isn't exactly ideal on it's own for this.

-r.


-----Original Message-----
From: Pons [mailto:pons at gmx.li]
Sent: Tuesday, February 24, 2004 6:33 AM
To: freebsd-security at freebsd.org
Subject: improve ipfw rules


I have configured a FreeBSD 5.1 rel box 2 NIC's (Ext.ip/Int.ip)
with ipfw/natd/squid the setup is working



More information about the freebsd-security mailing list