nanog mailing list archives

Re: how statefull firewall works for udp?


From: "Mike." <the.lists () mgm51 com>
Date: Fri, 21 Jan 2011 14:17:39 -0500

On 1/21/2011 at 9:39 PM Tarig Ahmed wrote:

|Dear All
|Hi
|
|Default configuration for statefull firewall is to allow traffic form

|TRUST ZONE to UNTRUST ZONE.
|
|As I Know those device will use some feilds in the TCP Header.
|
|But, how the firewall will handle this policy for none TCP traffics  
|(udp, icmp, and IPsec)?
|
|I think understanding this will help me in the designing.
|
|Thanks
 =============



Here's one way it is done:
http://www.openbsd.org/faq/pf/filter.html#udpstate





Current thread: