Problem receiving broadcast packets
Craig Watkinson <[email protected]> Fri, 18 Mar 2011 11:24:20 +0000
| Newsgroups | gmane.comp.security.firewalls.ipfilter |
|---|---|
| Message-ID | <18954_1300447628_4D83418B_18954_4141_1_SNT115-W28C29DEA12768E34471CA092B00@phx.gbl> |
--_07bfcad4-6edd-41da-8054-53ff39eb09f9_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
Hello=2C
we have some Solaris 10 servers running the following version of ipfilter:
ipf: IP Filter: v4.1.9 (592)
Kernel: IP Filter: v4.1.9
Running: no
Log=20
Flags: 0 =3D none set
Default: nomatch -> block all=2C Logging:=20
available
Active list: 0
Feature mask: 0x107
The following broadcast packets are being blocked inbound according to ipmo=
n.
17/03/2011 18:19:04.498382 e1000g0=20
@0:43 b 10.239.139.32=2C45960 -> 255.255.255.255=2C5735 PR udp len 20 181 I=
N=20
low-ttl
17/03/2011 18:19:04.498485 e1000g2 @0:43 b 10.239.138.32=2C45960 ->=20
255.255.255.255=2C5735 PR udp len 20 181 IN low-ttl
The inbound rules are below=2C however I would expect the highlighted line =
(***) to allow the packet. To allow inbound packets to 255.255.255.255 do w=
e need to explicitly use this address=2C or should "any" be allowing this i=
n?=20
pass in quick on lo0 all keep state keep frags
pass in quick from=20
172.21.1.4/32 to any port =3D 22 keep state keep frags
pass in quick from=20
172.21.1.6/32 to any port =3D 22 keep state keep frags
pass in quick from=20
10.239.138.100/32 to any port =3D 22 keep state keep frags
pass in quick from=20
10.239.162.100/32 to any port =3D 22 keep state keep frags
pass in quick from=20
10.239.158.39/32 to any port =3D 22 keep state keep frags
pass in quick from=20
10.239.158.40/32 to any port =3D 22 keep state keep frags
pass in quick from=20
10.239.158.41/32 to any port =3D 22 keep state keep frags
pass in quick from=20
10.239.162.30/32 to any port =3D 22 keep state keep frags
pass in quick from=20
10.239.162.31/32 to any port =3D 22 keep state keep frags
pass in quick from=20
10.239.162.32/32 to any port =3D 22 keep state keep frags
block in quick from=20
any to any port =3D 22
pass in quick from 10.239.128.0/17 to any port =3D 1521=20
keep state keep frags
pass in quick from 10.239.128.0/17 to any port =3D 3032=20
keep state keep frags
pass in quick from 10.239.128.0/17 to any port =3D 3232=20
keep state keep frags
pass in quick from 10.239.128.0/17 to any port =3D 7565=20
keep state keep frags
pass in quick from 10.239.128.0/17 to any port =3D 7778=20
keep state keep frags
pass in quick from 10.239.128.0/17 to any port =3D 8598=20
keep state keep frags
pass in quick from 10.239.128.0/17 to any port =3D 9998=20
keep state keep frags
pass in quick from 10.239.128.0/17 to any port =3D 21807=20
keep state keep frags
pass in quick from 10.239.128.0/17 to any port =3D 21808=20
keep state keep frags
pass in quick from 10.239.128.0/17 to any port =3D 21809=20
keep state keep frags
pass in quick from 10.239.128.0/17 to any port =3D 21810=20
keep state keep frags
pass in quick from 10.239.128.0/17 to any port =3D 21901=20
keep state keep frags
pass in quick proto udp from any to any port =3D 5735=20
keep state (***)
pass in quick proto udp from any to any port =3D 5736 keep=20
state
pass in quick proto tcp from any to any port =3D 3153 keep state
pass=20
in quick proto tcp from any to any port =3D 5735 keep state
pass in quick proto=20
tcp from any to any port =3D 5736 keep state
pass in quick proto udp from=20
10.239.138.100/32 to any port =3D snmpd keep state keep frags
pass in quick=20
proto udp from 10.239.162.100/32 to any port =3D snmpd keep state keep=20
frags
pass in quick from 172.17.26.28/32 to any port =3D 3144 keep state keep=20
frags
pass in quick from 172.17.26.30/32 to any port =3D 3144 keep state keep=20
frags
pass in quick from 172.17.23.58/32 to any port =3D 3144 keep state keep=20
frags
pass in quick from 172.17.23.59/32 to any port =3D 3144 keep state keep=20
frags
pass in quick from 172.17.23.60/32 to any port =3D 3144 keep state keep=20
frags
pass in quick from 172.17.26.28/32 to any port =3D 443 keep state keep=20
frags
pass in quick from 172.17.26.30/32 to any port =3D 443 keep state keep=20
frags
pass in quick from 172.17.23.58/32 to any port =3D 443 keep state keep=20
frags
pass in quick from 172.17.23.59/32 to any port =3D 443 keep state keep=20
frags
pass in quick from 172.17.23.60/32 to any port =3D 443 keep state keep=20
frags
pass in quick proto icmp from any to any
block in log quick=20
all
Thanks Craig
=
--_07bfcad4-6edd-41da-8054-53ff39eb09f9_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
<html>
<head>
<style><!--
.hmmessage P
{
margin:0px=3B
padding:0px
}
body.hmmessage
{
font-size: 10pt=3B
font-family:Tahoma
}
--></style>
</head>
<body class=3D'hmmessage'>
Hello=2C<br><br>we have some Solaris 10 servers running the following versi=
on of ipfilter:<br><br>ipf: IP Filter: v4.1.9 (592)<br>Kernel: IP Filter: v=
4.1.9<br>Running: no<br>Log=20
Flags: 0 =3D none set<br>Default: nomatch ->=3B block all=2C Logging:=20
available<br>Active list: 0<br>Feature mask: 0x107<br><br>The following bro=
adcast packets are being blocked inbound according to ipmon.<br><br><font s=
tyle=3D"font-size: 10pt=3B" color=3D"#ff0000" face=3D"Arial" size=3D"2"><st=
rong>17/03/2011 18:19:04.498382 e1000g0=20
@0:43 b 10.239.139.32=2C45960 ->=3B 255.255.255.255=2C5735 PR udp len 20 =
181 IN=20
low-ttl<br>17/03/2011 18:19:04.498485 e1000g2 @0:43 b 10.239.138.32=2C45960=
->=3B=20
255.255.255.255=2C5735 PR udp len 20 181 IN low-ttl<br></strong></font><br>=
The inbound rules are below=2C however I would expect the highlighted line =
(***) to allow the packet. To allow inbound packets to 255.255.255.255 do w=
e need to explicitly use this address=2C or should "any" be allowing this i=
n? <br><br><div>pass in quick on lo0 all keep state keep frags<br>pass in q=
uick from=20
172.21.1.4/32 to any port =3D 22 keep state keep frags<br>pass in quick fro=
m=20
172.21.1.6/32 to any port =3D 22 keep state keep frags<br>pass in quick fro=
m=20
10.239.138.100/32 to any port =3D 22 keep state keep frags<br>pass in quick=
from=20
10.239.162.100/32 to any port =3D 22 keep state keep frags<br>pass in quick=
from=20
10.239.158.39/32 to any port =3D 22 keep state keep frags<br>pass in quick =
from=20
10.239.158.40/32 to any port =3D 22 keep state keep frags<br>pass in quick =
from=20
10.239.158.41/32 to any port =3D 22 keep state keep frags<br>pass in quick =
from=20
10.239.162.30/32 to any port =3D 22 keep state keep frags<br>pass in quick =
from=20
10.239.162.31/32 to any port =3D 22 keep state keep frags<br>pass in quick =
from=20
10.239.162.32/32 to any port =3D 22 keep state keep frags<br>block in quick=
from=20
any to any port =3D 22<br>pass in quick from 10.239.128.0/17 to any port =
=3D 1521=20
keep state keep frags<br>pass in quick from 10.239.128.0/17 to any port =3D=
3032=20
keep state keep frags<br>pass in quick from 10.239.128.0/17 to any port =3D=
3232=20
keep state keep frags<br>pass in quick from 10.239.128.0/17 to any port =3D=
7565=20
keep state keep frags<br>pass in quick from 10.239.128.0/17 to any port =3D=
7778=20
keep state keep frags<br>pass in quick from 10.239.128.0/17 to any port =3D=
8598=20
keep state keep frags<br>pass in quick from 10.239.128.0/17 to any port =3D=
9998=20
keep state keep frags<br>pass in quick from 10.239.128.0/17 to any port =3D=
21807=20
keep state keep frags<br>pass in quick from 10.239.128.0/17 to any port =3D=
21808=20
keep state keep frags<br>pass in quick from 10.239.128.0/17 to any port =3D=
21809=20
keep state keep frags<br>pass in quick from 10.239.128.0/17 to any port =3D=
21810=20
keep state keep frags<br>pass in quick from 10.239.128.0/17 to any port =3D=
21901=20
keep state keep frags<br><b>pass in quick proto udp from any to any port =
=3D 5735=20
keep state  =3B  =3B  =3B  =3B  =3B =3B (***)</b><b=
r>pass in quick proto udp from any to any port =3D 5736 keep=20
state<br>pass in quick proto tcp from any to any port =3D 3153 keep state<b=
r>pass=20
in quick proto tcp from any to any port =3D 5735 keep state<br>pass in quic=
k proto=20
tcp from any to any port =3D 5736 keep state<br>pass in quick proto udp fro=
m=20
10.239.138.100/32 to any port =3D snmpd keep state keep frags<br>pass in qu=
ick=20
proto udp from 10.239.162.100/32 to any port =3D snmpd keep state keep=20
frags<br>pass in quick from 172.17.26.28/32 to any port =3D 3144 keep state=
keep=20
frags<br>pass in quick from 172.17.26.30/32 to any port =3D 3144 keep state=
keep=20
frags<br>pass in quick from 172.17.23.58/32 to any port =3D 3144 keep state=
keep=20
frags<br>pass in quick from 172.17.23.59/32 to any port =3D 3144 keep state=
keep=20
frags<br>pass in quick from 172.17.23.60/32 to any port =3D 3144 keep state=
keep=20
frags<br>pass in quick from 172.17.26.28/32 to any port =3D 443 keep state =
keep=20
frags<br>pass in quick from 172.17.26.30/32 to any port =3D 443 keep state =
keep=20
frags<br>pass in quick from 172.17.23.58/32 to any port =3D 443 keep state =
keep=20
frags<br>pass in quick from 172.17.23.59/32 to any port =3D 443 keep state =
keep=20
frags<br>pass in quick from 172.17.23.60/32 to any port =3D 443 keep state =
keep=20
frags<br>pass in quick proto icmp from any to any<br><strong>block in log q=
uick=20
all<br></strong></div><br><br>Thanks Craig<br> </body>
</html>=
--_07bfcad4-6edd-41da-8054-53ff39eb09f9_--