Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

ipfw interfering with dhcp?

1 view
Skip to first unread message

Mac Dude

unread,
Nov 3, 2009, 1:03:16 AM11/3/09
to
Hi,

I am running ipfw with a custom setup through Waterroof on my Macbook
(Leo 10.5.8). In some areas like this hotel I am in now I seem to be
unable to get a dhcp address unless I turn the firewall off. Is this
normal? In other areas I have no such issues with ipfw on.

Macc Dude.

Kevin McMurtrie

unread,
Nov 3, 2009, 1:52:57 AM11/3/09
to
In article <do-0A8DB3.22...@freenews.netfront.net>,
Mac Dude <d...@not.use> wrote:

ipfw can break anything with the wrong configuration. It operates at a
very low level in the system.
--
I won't see Goolge Groups replies because I must filter them as spam

David Stone

unread,
Nov 3, 2009, 9:31:04 AM11/3/09
to
In article <4aefd349$0$1992$742e...@news.sonic.net>,
Kevin McMurtrie <kevi...@sonic.net> wrote:

> In article <do-0A8DB3.22...@freenews.netfront.net>,
> Mac Dude <d...@not.use> wrote:
>
> > Hi,
> >
> > I am running ipfw with a custom setup through Waterroof on my Macbook
> > (Leo 10.5.8). In some areas like this hotel I am in now I seem to be
> > unable to get a dhcp address unless I turn the firewall off. Is this
> > normal? In other areas I have no such issues with ipfw on.
> >
> > Macc Dude.
>
> ipfw can break anything with the wrong configuration. It operates at a
> very low level in the system.

Make sure logging is turned on. If you try and fail to establish a
dhcp connection, look in the log file to see what services/ports
were denied at the time of your attempted connection.* I can't offer
any more specific suggestions, as I don't (currently) have ipfw
enabled on my laptop (only Mac's application firewall), and my
desktop is on a static ip.

* View the log in realtime via console while trying to establish
a connection if possible!

Mac Dude

unread,
Nov 3, 2009, 10:06:03 PM11/3/09
to
In article <no.email-DAFCA2...@news1.chem.utoronto.ca>,
David Stone <no.e...@domain.invalid> wrote:

Hmm, good idea; why didn't I think of that...:-)

Anyway, thanks; I'll try to do that,

M.D.

0 new messages