Re: (PM) Filters AGAIN...

Stavros Patiniotis (stavros@esc.net.au)
Thu, 28 May 1998 15:56:09 +0930 (CST)

On Thu, 28 May 1998, Stavros Patiniotis wrote:

>
>
> On Thu, 28 May 1998, Martin Rheumer wrote:
>
> > I have tried and tried to get a grasp on this and would
> > love if someone said oh you idiot do this..
> >
> > I have the following rules...
> >
> > 1 deny 0.0.0.0/0 0.0.0.0/0 tcp dst eq 137
> > 2 deny 0.0.0.0/0 0.0.0.0/0 tcp dst eq 138
> > 3 deny 0.0.0.0/0 0.0.0.0/0 tcp dst eq 139
> >
> > for a filter called ether.in
> >
> > and
> >
> > 1 deny 0.0.0.0/0 0.0.0.0/0 tcp dst eq 137
> > 2 deny 0.0.0.0/0 0.0.0.0/0 tcp dst eq 138
> > 3 deny 0.0.0.0/0 0.0.0.0/0 tcp dst eq 139
> >
> > And then I have
>
> you may want to 'log' the above 3 denies, also for your records ;)
>
> > set ether0 ifilter ether.in and hey presto
> > the Portmaster stops responding..
>
> you need to add a
>
> 4 permit 0.0.0.0/0 0.0.0.0/0

ahhh this doesn't work with permit, only with deny.

Try

set filter ether.in 4 permit

this will work.

> so it can permit any other traffic.

Regards,

Stavros Patiniotis
------------------------------------------------------------------------------
-System Administrator / Network Manager Escape.Net -
- 465b South Rd -
-email: stavros@esc.net.au Keswick SA 5035 -
-URL: http://www.esc.net.au Ph 82932526 Fax 82932949-
------------------------------------------------------------------------------

-
To unsubscribe, email 'majordomo@livingston.com' with
'unsubscribe portmaster-users' in the body of the message.
Searchable list archive: <URL:http://www.livingston.com/Tech/archive/>