ipfilter keep state troubles

From: Jeroen van Nieuwenhuizen <jnieuwen_at_jeroen.se>
Date: Mon, 18 Oct 2004 14:31:41 +0200
Hello all,

Using the RELENG_5_3 tag I ran into some troubles using ipfilter
compiled into the kernel with default policy set to block. The
problem is that I can no longer ping the local interface
with the command: ping 127.0.0.1.

Using a simpeler firewall configuration I noted that
it has probably something to do with the keep state
directive

Using the rules
pass out all
pass in all

I can ping to 127.0.0.1

Using the rules
pass out all keep state
pass in all
I can not ping to 127.0.0.1

Anyone any ideas?

Kind regards,

Jeroen

-- 
Jeroen van Nieuwenhuizen (M.Sc[CompSc])
jnieuwen_at_jeroen.se     http://www.jeroen.se
I know I'm not perfect but I can smile


Received on Mon Oct 18 2004 - 10:31:44 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:38:18 UTC