Re: (PM) Filters AGAIN...

Stavros Patiniotis (stavros@esc.net.au)
Thu, 28 May 1998 15:48:10 +0930 (CST)

On Thu, 28 May 1998, Martin Rheumer wrote:

> I have tried and tried to get a grasp on this and would
> love if someone said oh you idiot do this..
>
> I have the following rules...
>
> 1 deny 0.0.0.0/0 0.0.0.0/0 tcp dst eq 137
> 2 deny 0.0.0.0/0 0.0.0.0/0 tcp dst eq 138
> 3 deny 0.0.0.0/0 0.0.0.0/0 tcp dst eq 139
>
> for a filter called ether.in
>
> and
>
> 1 deny 0.0.0.0/0 0.0.0.0/0 tcp dst eq 137
> 2 deny 0.0.0.0/0 0.0.0.0/0 tcp dst eq 138
> 3 deny 0.0.0.0/0 0.0.0.0/0 tcp dst eq 139
>
> And then I have

you may want to 'log' the above 3 denies, also for your records ;)

> set ether0 ifilter ether.in and hey presto
> the Portmaster stops responding..

you need to add a

4 permit 0.0.0.0/0 0.0.0.0/0

so it can permit any other traffic.

Regards,

Stavros Patiniotis
------------------------------------------------------------------------------
-System Administrator / Network Manager Escape.Net -
- 465b South Rd -
-email: stavros@esc.net.au Keswick SA 5035 -
-URL: http://www.esc.net.au Ph 82932526 Fax 82932949-
------------------------------------------------------------------------------

-
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe portmaster-users' in the body of the message.
Searchable list archive: <URL:http://www.livingston.com/Tech/archive/>