Re: svn commit: r49600 - head/en_US.ISO8859-1/books/handbook/firewalls

Maxim Konovalov <[email protected]>
Newsgroups gmane.os.freebsd.devel.cvs.doc
Message-ID <[email protected]>
[...]
> > I'd remove the "setup" keyword from the command.  Let me know if I can
> > go ahead with this change.
>
> It's okay with me.  Er, "Approved".  It would be really nice if you could test
> and verify it, but not required.
>
Done.

Just a side note: the chapter still needs more work -- e.g. there is
the time service rule in the ipf (not sure if it is ever functional on
FreeBSD these days) sub-chapter.

There is a quite dubious 310 rule in the ipfw example (dru@ cc'ed)
that claims that denies "Deny public pings" but in fact denies all
ICMP not just ICMP echo request/response or types 9/0.  It means it
could break the path mtu discovery mechanism that relies on ICMP type
3 code 4 messages.

I must admit I haven't read the chapter carefully.

Thanks,

Maxim

-- 
Maxim Konovalov
_______________________________________________
[email protected] mailing list
https://lists.freebsd.org/mailman/listinfo/svn-doc-all
To unsubscribe, send any mail to "[email protected]"
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.