ipfw reject with unreach strange behavior

Liste des GroupesRevenir à cubf misc 
Sujet : ipfw reject with unreach strange behavior
De : mm (at) *nospam* dorfdsl.de (Marco Moock)
Groupes : comp.unix.bsd.freebsd.misc
Date : 08. Jun 2025, 15:52:21
Autres entêtes
Organisation : A noiseless patient Spider
Message-ID : <20250608165221.4f798afa@ryz.dorfdsl.de>
User-Agent : Claws Mail 4.3.1 (GTK 3.24.49; x86_64-pc-linux-gnu)
Hello!

My goal is to have a ruleset that rejects the packet with ICMP
admin-prohib using IPFW.

I know that ICMPv6 and ICMP (IPv4) are different, so the first question
is: Are there 2 rules required?

I currently have

m@vm_teufel:~ $ sudo ipfw list
00100 allow ip from any to any via lo0
00200 deny ip from any to 127.0.0.0/8
00300 deny ip from 127.0.0.0/8 to any
00400 deny ip from any to ::1
00500 deny ip from ::1 to any
00600 allow ipv6-icmp from :: to ff02::/16
00700 allow ipv6-icmp from fe80::/10 to fe80::/10
00800 allow ipv6-icmp from fe80::/10 to ff02::/16
00900 allow ipv6-icmp from any to any icmp6types 1
01000 allow ipv6-icmp from any to any icmp6types 2,135,136
01100 check-state :default
01200 allow tcp from me to any established
01300 allow tcp from me to any setup keep-state :default
01400 allow udp from me to any keep-state :default
01500 allow icmp from me to any keep-state :default
01600 allow ipv6-icmp from me to any keep-state :default
01700 allow udp from 0.0.0.0 68 to 255.255.255.255 67 out
01800 allow udp from any 67 to me 68 in
01850 allow tcp from any to me 22 in
01900 allow udp from any 67 to 255.255.255.255 68 in
02000 allow udp from fe80::/10 to me 546 in
02100 allow icmp from any to any icmptypes 8
02200 allow ipv6-icmp from any to any icmp6types 128,129
02300 allow icmp from any to any icmptypes 3,4,11
02400 allow ipv6-icmp from any to any icmp6types 3
65000 count ip from any to any
65500 unreach filter-prohib log ip4 from any to any
65501 unreach6 admin-prohib log ip6 from any to any
65535 deny ip from any to any #this is implicit

The variant for IPv4 (65500) doesn't work, the packet is silently
dropped and not logged, 65501 works and is being logged.

Does anybody here know what the fault is?

--
kind regards
Marco

Send spam to 1749393378muell@stinkedores.dorfdsl.de


Date Sujet#  Auteur
8 Jun 25 o ipfw reject with unreach strange behavior1Marco Moock

Haut de la page

Les messages affichés proviennent d'usenet.

NewsPortal