next up previous
Next: Bibliography Up: IP-Filter Previous: Restarting the System

Testing IP-Filter

Once you have both DP and IP-Filter up and running, you should be able to connect up to your ISP via the any system. You can test the system by trying to make connections to the outside world via your private network systems -- win95 and linux for the example.

Manual pages for the IP-Filter programs can be found in /opt/ipf/man If you are doing a lot of testing, then you will probably want to add this to your MANPATH environment variable.

You can examine the state of NAT by using /sbin/ipnat -l This command will print out the current set of NAT rules and the current set of redirections.

You can examine the filtering process by using /opt/ipf/bin/ipmon -t This command prints out a continuous trace of the logged packets passing through the filter. You can examine the filtering statistics by using /sbin/ipfstat



Doug Palmer 2003-02-15