Re: laptop firewall rules
Giorgos Keramidas <[email protected]>
| Newsgroups | gmane.os.freebsd.devel.mobile,gmane.os.freebsd.questions |
|---|---|
| Message-ID | <[email protected]> |
On 2005-10-31 16:45, Giorgos Keramidas <[email protected]> wrote: >On 2005-10-30 18:23, Eric F Crist <[email protected]> wrote: >>On Oct 30, 2005, at 4:41 PM, [email protected] wrote: >>> Does anyone have a good example of a firewall ruleset for a >>> wireless interface in a laptop, or a pointer to documentation? >>> I want to use IPFilter on 6.0 rc1. I want to let all >>> connections out and keep state, but block all incoming from >>> the outside. >> >> That ruleset is easy: >> >> ipfw add check-state >> ipfw add allow tcp from me to any setup keep-state >> ipfw add allow tcp from any to any established >> ipfw add deny from any to me in > > No, please! > > If you are using "keep-state", when "allow all established" is > hardly ever a good idea. "when" = "then", of course. _______________________________________________ [email protected] mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-mobile To unsubscribe, send any mail to "[email protected]"