[135326] in North American Network Operators' Group
Re: how statefull firewall works for udp?
daemon@ATHENA.MIT.EDU (Mike.)
Fri Jan 21 14:17:50 2011
In-Reply-To: <BLU0-SMTP53809E496540FA4BD76743BBF80@phx.gbl>
Date: Fri, 21 Jan 2011 14:17:39 -0500
From: "Mike." <the.lists@mgm51.com>
To: "nanog@nanog.org list" <nanog@nanog.org>,
"African Network Operators" <afnog@afnog.org>
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
On 1/21/2011 at 9:39 PM Tarig Ahmed wrote:
|Dear All
|Hi
|
|Default configuration for statefull firewall is to allow traffic form
|TRUST ZONE to UNTRUST ZONE.
|
|As I Know those device will use some feilds in the TCP Header.
|
|But, how the firewall will handle this policy for none TCP traffics
|(udp, icmp, and IPsec)?
|
|I think understanding this will help me in the designing.
|
|Thanks
=============
Here's one way it is done:
http://www.openbsd.org/faq/pf/filter.html#udpstate