ipf & icmp pakety - kde je problem ?

Brano Vislocky brano at zmail.sk
Fri Jul 19 12:30:03 CEST 2002


Milos Urbanek wrote:
> On Wed, Jul 17, 2002 at 04:16:44PM +0200, Juraj Lutter wrote:
> 
>>On Wed, Jul 17, 2002 at 04:05:42PM +0200, Brano Vislocky wrote:
>>
>>>Ahojte,
>>>block  in log on ep1 all head 1
>>>pass in quick on ep1 proto icmp from any to 1.2.3.4/32 icmp-type 0 group 1
>>>pass in quick on ep1 proto icmp from any to 1.2.3.4/32 icmp-type 11 group 1
>>>
>>>
>>>predpokladam, ze 1. riadok je 'default' pravidlo pre group 1
>>>
>>>no a problem je ten, ze ked ping-ujem kartu ep1, tak sa mi v logoch 
>>>objavi take nieco:
>>>
>>>ipmon: 15:05:40.992524 ep1 @0:6 b x.x.x.x -> 1.2.3.4 PR icmp len 20 84 
>>>icmp echo/0 IN
>>
> 
> co takhle zmenit
> icmp-type 0 na icmp-type 8  a pridat keep state?
> 
> #define ICMP_ECHO               8               /* echo service */
> #define ICMP_ECHOREPLY          0               /* echo reply */
> 
> 
> Milos

bingo !   :)

dakujem

Brano




More information about the Users-l mailing list