tramX
NoDeny
Постоялец
Карма: 1
Offline
Сообщений: 108
|
|
« Ответ #27 : 11 Августа 2009, 13:01:13 » |
|
nodeny# ifconfig re0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=389b<RXCSUM,TXCSUM,VLAN_MTU,VLAN_HWTAGGING,VLAN_HWCSUM,WOL_UCAST ,WOL_MCAST,WOL_MAGIC> ether 00:24:8c:e6:ff:2c inet 192.168.5.55 netmask 0xffffff00 broadcast 192.168.5.255 media: Ethernet autoselect (100baseTX <full-duplex>) status: active rl0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=8<VLAN_MTU> ether 00:30:4f:69:13:1c inet 192.168.4.1 netmask 0xffffff00 broadcast 192.168.4.255 media: Ethernet autoselect (100baseTX <full-duplex>) status: active rl1: flags=8802<BROADCAST,SIMPLEX,MULTICAST> metric 0 mtu 1500 options=8<VLAN_MTU> ether 00:30:4f:67:d6:66 media: Ethernet autoselect status: no carrier pfsync0: flags=0<> metric 0 mtu 1460 syncpeer: 224.0.0.240 maxupd: 128 lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> metric 0 mtu 16384 inet6 fe80::1%lo0 prefixlen 64 scopeid 0x5 inet6 ::1 prefixlen 128 inet 127.0.0.1 netmask 0xff000000 pflog0: flags=141<UP,RUNNING,PROMISC> metric 0 mtu 33204 ng0: flags=88d1<UP,POINTOPOINT,RUNNING,NOARP,SIMPLEX,MULTICAST> metric 0 mtu 576 inet 192.168.5.55 --> 172.16.1.2 netmask 0xffffffff
nodeny# ipfw show 00040 0 0 allow tcp from any to me dst-port 1723 in 00041 0 0 allow tcp from me 1723 to any out 00042 0 0 allow gre from any to any 00050 73 6572 allow tcp from any to me dst-port 22 00051 56 8280 allow tcp from me 22 to any 00110 346 114198 allow ip from any to any via lo0 00120 142 8553 skipto 1000 ip from me to any 00130 0 0 deny icmp from any to any in icmptypes 5,9,13,14,15,16,17 00160 151 13390 skipto 2000 ip from any to me 00200 1453 377209 skipto 500 ip from any to any via re0 00300 866 116576 skipto 4500 ip from any to any in 00400 651 267225 skipto 450 ip from any to any recv re0 00420 0 0 divert 1 ip from any to any 00450 651 267225 divert 2 ip from any to any 00490 651 267225 allow ip from any to any 00500 701 272268 skipto 32500 ip from any to any in 00510 752 104941 divert 1 ip from any to any 00540 752 104941 allow ip from any to any 01000 0 0 allow udp from any 53,7723 to any 01010 18 936 allow tcp from any to any setup keep-state 01020 57 5964 allow udp from any to any keep-state 01100 89 5340 allow ip from any to any 02000 0 0 check-state 02010 89 5340 allow icmp from any to any 02020 0 0 allow tcp from any to any dst-port 80,443 02050 40 4363 deny ip from any to any via re0 02060 0 0 allow udp from any to any dst-port 53,7723 02100 0 0 deny ip from any to any 05000 98 10153 deny ip from not table(0) to any 05001 0 0 skipto 5010 ip from table(127) to table(126) 05002 752 104941 skipto 5030 ip from any to not table(2) 05003 0 0 deny ip from any to not table(1) 05004 0 0 pipe tablearg ip from table(21) to any 05005 0 0 deny ip from any to any 05010 0 0 pipe tablearg ip from table(127) to any 05030 0 0 deny tcp from table(15) to any dst-port 25 05400 752 104941 pipe tablearg ip from table(11) to any 32000 0 0 deny ip from any to any 32490 16 1482 deny ip from any to any 33000 0 0 pipe tablearg ip from table(126) to table(127) 33001 701 272268 skipto 33010 ip from not table(2) to any 33002 0 0 pipe tablearg ip from any to table(20) 33003 0 0 deny ip from any to any 33400 651 267225 pipe tablearg ip from any to table(10) 65535 50 5043 deny ip from any to any
nodeny# netstat -rn Routing tables
Internet: Destination Gateway Flags Refs Use Netif Expire default 192.168.5.1 UGS 0 2890 re0 127.0.0.1 127.0.0.1 UH 0 533 lo0 172.16.1.2 192.168.5.55 UH 1 3871 ng0 192.168.4.0/24 link#2 UC 0 0 rl0 192.168.5.0/24 link#1 UC 0 0 re0 192.168.5.1 00:19:21:4b:91:27 UHLW 2 9 re0 694 192.168.5.32 00:50:8d:4c:5b:07 UHLW 1 3 re0 1198
Отключаю IPFW страницы грузятся.
|