Is there anyone out there using FireWall-1 software that has
managed to get a range of TCP/UDP ports let through?  (ie. UDP
ports 6970-7170 for ReadAudio ...)  The manual says nothing about this.

Any help would be appreciated!

Tom Wentworth     (603) 883-0220
AimTech Corporation-    Nashua NH



1. ipchains/TCP/UDP, Why should I open UDP ports so that my TCP ports can work?


I have set up firewall to accept some ports.
/sbin/ipchains -F input
/sbin/ipchains -P input ACCEPT
/sbin/ipchains -A input -p TCP -s 0/0 --dport ssh -j ACCEPT
/sbin/ipchains -A input -p UDP -s 0/0 --dport ssh -j ACCEPT

Then I want to lock down all other ports.
/sbin/ipchains -A input -p TCP -s ! -j DENY

#??? what's wrong with this UDP ???
/sbin/ipchains -A input -p UDP -s ! -j DENY

If I comment out the UDP line, I can ssh into firewall from outside.
If I don't comment out that line, I can no longer ssh into firewall from

Why should I open UDP ports so that my TCP ports can work?

Thanks for any help.

Ed Wu

