[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: ICMP and IPfilter



Clay Dillard (clay_(_at_)_454homenet_(_dot_)_tzo_(_dot_)_com) wrote:
> Can someone please help me to get icmp (like traceroute and ping) to work

These are my icmp rules:

# icmp rules
# http://www.shmoo.com/mail/firewalls/jan01/msg00015.shtml

# Echo reply
pass in quick on ne3 proto icmp from any to yourip/32 icmp-type  0 keep state

# Destination unreachable
pass in quick on ne3 proto icmp from any to yourip/32 icmp-type  3 keep state

# Source Quench
pass in quick on ne3 proto icmp from any to yourip/32 icmp-type  4 keep state

# Echo
pass in quick on ne3 proto icmp from any to yourip/32 icmp-type  8 keep state

# Time exeeded
pass in quick on ne3 proto icmp from any to yourip/32 icmp-type 11 keep state

# Parameter Problem
pass in quick on ne3 proto icmp from any to yourip/32 icmp-type 12 keep state

And these are my ipnat rules:
# startcommand : /sbin/ipnat -CF -f /etc/ipnat.rules ; ipf -y

map ne3 192.168.1.0/24 -> ne3/32 portmap tcp/udp 10000:20000
map ne3 192.168.1.0/24 -> ne3/32


Cya, Han.



Visit your host, monkey.org