root@fw00:~ # ipfw -a list00100 0 0 allow pfsync from any to any00110 0 0 allow carp from any to any00120 0 0 allow ip from any to any layer2 mac-type 0x0806,0x803500130 0 0 allow ip from any to any layer2 mac-type 0x888e,0x88c700140 0 0 allow ip from any to any layer2 mac-type 0x8863,0x886400150 0 0 deny ip from any to any layer2 not mac-type 0x0800,0x86dd00200 0 0 skipto 60000 ip6 from ::1 to any00201 44 9156 skipto 60000 ip4 from 127.0.0.0/8 to any00202 0 0 skipto 60000 ip6 from any to ::100203 0 0 skipto 60000 ip4 from any to 127.0.0.0/801002 36 3560 skipto 60000 udp from any to 10.8.6.254 dst-port 53 keep-state01002 117 13994 skipto 60000 ip from any to { 255.255.255.255 or 10.8.6.254 } in01002 160 21192 skipto 60000 ip from { 255.255.255.255 or 10.8.6.254 } to any out01002 0 0 skipto 60000 icmp from { 255.255.255.255 or 10.8.6.254 } to any out icmptypes 001002 0 0 skipto 60000 icmp from any to { 255.255.255.255 or 10.8.6.254 } in icmptypes 801003 0 0 skipto 60000 udp from any to 192.168.3.254 dst-port 53 keep-state01003 0 0 skipto 60000 ip from any to { 255.255.255.255 or 192.168.3.254 } in01003 0 0 skipto 60000 ip from { 255.255.255.255 or 192.168.3.254 } to any out01003 0 0 skipto 60000 icmp from { 255.255.255.255 or 192.168.3.254 } to any out icmptypes 001003 0 0 skipto 60000 icmp from any to { 255.255.255.255 or 192.168.3.254 } in icmptypes 865535 9056022 8639833830 allow ip from any to any
11 WAN ip 10.8.6.0/24 any DownQueue 21 WAN ip any 10.8.6.0/24 UpQueue
root@fw00:~ # ipfw /usr/local/etc/ipfw.rulesAre you sure? [yn] yFlushed all rules.00100 allow pfsync from any to any00110 allow carp from any to any00120 allow ip from any to any layer2 mac-type 0x0806,0x803500130 allow ip from any to any layer2 mac-type 0x888e,0x88c700140 allow ip from any to any layer2 mac-type 0x8863,0x886400150 deny ip from any to any layer2 not mac-type 0x0800,0x86dd00200 skipto 60000 ip6 from ::1 to any00201 skipto 60000 ip4 from 127.0.0.0/8 to any00202 skipto 60000 ip6 from any to ::100203 skipto 60000 ip4 from any to 127.0.0.0/801002 skipto 60000 udp from any to 10.8.6.254 dst-port 53 keep-state01002 skipto 60000 ip from any to { 255.255.255.255 or 10.8.6.254 } in01002 skipto 60000 ip from { 255.255.255.255 or 10.8.6.254 } to any out01002 skipto 60000 icmp from { 255.255.255.255 or 10.8.6.254 } to any out icmptypes 001002 skipto 60000 icmp from any to { 255.255.255.255 or 10.8.6.254 } in icmptypes 801003 skipto 60000 udp from any to 192.168.3.254 dst-port 53 keep-state01003 skipto 60000 ip from any to { 255.255.255.255 or 192.168.3.254 } in01003 skipto 60000 ip from { 255.255.255.255 or 192.168.3.254 } to any out01003 skipto 60000 icmp from { 255.255.255.255 or 192.168.3.254 } to any out icmptypes 001003 skipto 60000 icmp from any to { 255.255.255.255 or 192.168.3.254 } in icmptypes 8Line 53: hostname ``l2tp'' unknown
add 1003 skipto 60000 icmp from any to { 255.255.255.255 or 192.168.3.254 } in icmptypes 8add 1005 skipto 60000 udp from any to l2tp dst-port 53 keep-stateadd 1005 skipto 60000 ip from any to { 255.255.255.255 or l2tp } inadd 1005 skipto 60000 ip from { 255.255.255.255 or l2tp } to any outadd 1005 skipto 60000 icmp from { 255.255.255.255 or l2tp } to any out icmptypes 0add 1005 skipto 60000 icmp from any to { 255.255.255.255 or l2tp } in icmptypes 8