Alternative to null-routing in FreeBSD (using IPFW)

Instead of using null-routing, you can use IPFW to block the traffic (the advantages include being able to set the ICMP response type).  My favourite is to use “Communication prohibited by filter” response.

If you wanted to block in this way, you would use:

/sbin/ipfw add 01000 unreach filter-prohib ip from to me

You can also adapt the above to only include certain types of traffic which is where it is more flexible than null-routing.

Leave a Reply

Your email address will not be published. Required fields are marked *