Hi all,
I've simple ruleset mostly showed in freebsd wiki. All works, but sometimes ipfw blocks outbound connections on port 80 and 443, which has allowing rule. ipfw not totally blocks outbound connections, but only few ones.
Relevant rules are:
And in /var/log/security I've multiple records like :
I've simple ruleset mostly showed in freebsd wiki. All works, but sometimes ipfw blocks outbound connections on port 80 and 443, which has allowing rule. ipfw not totally blocks outbound connections, but only few ones.
Relevant rules are:
Code:
outport="$http,$https"
$cmd 00200 allow tcp from any to any $outport out via $ext setup keep-state
$cmd 00299 deny log all from any to any out via $ext
And in /var/log/security I've multiple records like :
Code:
Dec 17 00:41:12 myhostname kernel: ipfw: 299 Deny TCP 192.168.20.2:63924 149.20.1.201:80 out via re0
Dec 17 00:41:40 myhostname syslogd: last message repeated 4 times
Dec 17 00:42:09 myhostname kernel: ipfw: 299 Deny TCP 192.168.20.2:28472 213.138.116.73:80 out via re0
Dec 17 00:42:09 myhostname kernel: ipfw: 299 Deny TCP 192.168.20.2:63924 149.20.1.201:80 out via re0
Dec 17 00:42:54 myhostname kernel: ipfw: 299 Deny TCP 192.168.20.2:15146 213.138.116.73:80 out via re0
Dec 17 00:43:07 myhostname kernel: ipfw: 299 Deny TCP 192.168.20.2:63924 149.20.1.201:80 out via re0
Dec 17 00:43:13 myhostname kernel: ipfw: 299 Deny TCP 192.168.20.2:28472 213.138.116.73:80 out via re0
Dec 17 00:43:57 myhostname kernel: ipfw: 299 Deny TCP 192.168.20.2:15146 213.138.116.73:80 out via re0
Dec 17 00:44:11 myhostname kernel: ipfw: 299 Deny TCP 192.168.20.2:63924 149.20.1.201:80 out via re0
Dec 17 00:44:17 myhostname kernel: ipfw: 299 Deny TCP 192.168.20.2:28472 213.138.116.73:80 out via re0
Dec 17 00:45:01 myhostname kernel: ipfw: 299 Deny TCP 192.168.20.2:15146 213.138.116.73:80 out via re0
Dec 17 00:45:15 myhostname kernel: ipfw: 299 Deny TCP 192.168.20.2:63924 149.20.1.201:80 out via re0
Dec 17 00:45:21 myhostname kernel: ipfw: 299 Deny TCP 192.168.20.2:28472 213.138.116.73:80 out via re0
Dec 17 00:46:06 myhostname kernel: ipfw: 299 Deny TCP 192.168.20.2:15146 213.138.116.73:80 out via re0
Dec 17 00:46:19 myhostname kernel: ipfw: 299 Deny TCP 192.168.20.2:63924 149.20.1.201:80 out via re0
Dec 17 00:46:25 myhostname kernel: ipfw: 299 Deny TCP 192.168.20.2:28472 213.138.116.73:80 out via re0
Dec 17 00:47:09 myhostname kernel: ipfw: 299 Deny TCP 192.168.20.2:15146 213.138.116.73:80 out via re0
Dec 17 00:47:23 myhostname kernel: ipfw: 299 Deny TCP 192.168.20.2:63924 149.20.1.201:80 out via re0
Dec 17 00:48:27 myhostname syslogd: last message repeated 1 times
Dec 17 03:36:10 myhostname kernel: ipfw: 299 Deny TCP 192.168.20.2:25615 104.20.0.85:443 out via re0
Dec 17 03:36:48 myhostname syslogd: last message repeated 4 times
Dec 17 03:38:47 myhostname syslogd: last message repeated 3 times
Dec 17 03:39:27 myhostname syslogd: last message repeated 1 times
Dec 17 18:16:22 myhostname kernel: ipfw: Accounting cleared.
Dec 20 10:59:59 myhostname kernel: ipfw: 299 Deny TCP 192.168.20.2:52521 46.137.83.240:80 out via re0
Dec 20 11:01:03 myhostname syslogd: last message repeated 1 times
Dec 20 11:02:07 myhostname syslogd: last message repeated 1 times
Dec 20 11:04:15 myhostname syslogd: last message repeated 2 times