Re: ipfilter / ipnat quandry

2002-12-17 Thread Clifton Royston
On Tue, Dec 17, 2002 at 04:59:37PM -0600, Craig Boston wrote: > On Tue, 2002-12-17 at 13:02, Clifton Royston wrote: > > ipf does have the ability to more correctly simulate a closed port. > > I did a similar exercise on my personal OpenBSD firewall box earlier > > this year; I won't go through

Re: ipfilter / ipnat quandry

2002-12-17 Thread Craig Boston
On Tue, 2002-12-17 at 13:02, Clifton Royston wrote: > ipf does have the ability to more correctly simulate a closed port. > I did a similar exercise on my personal OpenBSD firewall box earlier > this year; I won't go through your whole ruleset, but basically for > every TCP port you block, you

Re: ipfilter / ipnat quandry

2002-12-17 Thread Clifton Royston
(This probably belonged on -security or -questions or someplace else...) > Date: Mon, 16 Dec 2002 13:55:48 -0500 > From: "Robin P. Blanchard" <[EMAIL PROTECTED]> > Subject: ipfilter / ipnat quandry > > - -STABLE (FreeBSD 4.7-STABLE #0: Mon Nov 25 14:22:58 EST 20