I use firehol for home PC.
Some sites not accessible for me, if firehol is up:
> tracepath freesource.info
 1:  send failed
     Resume: pmtu 65535
if firehol is down:
> tracepath freesource.info
1: (                              0.306ms
pmtu 1500 1: (
6.652ms 2:  breez.dobroe.ru (
9.752ms 3:  MSK13-l7713.transtelecom.net (
22.078ms 4:  SkyMedia10-gw.transtelecom.net (
asymm  6 210.133ms 5:  kiae2-Po-Agava-3.netflow.ru
(          asymm  7  27.035ms 6:  dimline.ru
(                           asymm  8  30.716ms reached
Resume: pmtu 1500 hops 6 back 8

### firehol.conf
interface eth0 home # eth0 lan network
        policy reject
        protection strong 10/sec 10
к тебе server "ssh postgres"   accept src "${trust_ips}"
        server "ftp http"       accept #src "${trust_ips}"
        server  icmp    accept limit 3/m 5

        server ident reject with tcp-reset

#       client "pop3 pop3s imap irc pptp dcc GRE dhcp dhcprelay dns ftp
http https ssh ping"   accept
        client all accept

interface ppp+ internet src not "${home_ips} ${UNROUTABLE_IPS}" # inet
        protection strong 10/sec 10
#       server ""       accept
        server ident reject with tcp-reset
        client all      accept

How to fix this?
Всего наилучшего! Григорий
greg [at] anastasia [dot] ru
Письмо отправлено: 2006/11/03 13:29

