Firewall settings unworkable

Tim Waugh twaugh at redhat.com
Fri Oct 1 14:15:09 UTC 2010


On Fri, 2010-10-01 at 15:07 +0100, David Howells wrote:
> The following works for UDP too:
> 
> 	-A INCOMING -m state --state RELATED,ESTABLISHED -j ACCEPT
> 
> Leastways, I can do AFS through my firewall with it.

Does that work for unicast replies to broadcast queries though?

e.g.

IP 10.1.1.8.33353 > 10.1.1.255.snmp:  GetRequest(28) 
.1.3.6.1.2.1.25.3.2.1.2.1

IP 10.1.1.7.snmp > 10.1.1.8.33353:  GetResponse(37) 
.1.3.6.1.2.1.25.3.2.1.2.1=.1.3.6.1.2.1.25.3.1.5

Tim.
*/

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 190 bytes
Desc: This is a digitally signed message part
Url : http://lists.fedoraproject.org/pipermail/devel/attachments/20101001/2b89b62e/attachment.bin 


More information about the devel mailing list