Sponsored in part by... Web Crossing WebCrossing Neighbors Creates Private Social Networks
Create a complete social network with your company or group's
own look. Scalable, extensible and extremely customizable.
Take a guided tour today <http://www.webcrossing.com/tour>

 [F] TidBITS  / TidBITS  / TidBITS Talk  /

Leopard firewall vs iChat over Bonjour

[jwbaxter]jwbaxter (apparently) - 09:43am Nov 19, 2007 PST
via email

Since updating to Leopard, I have been unable to use iChat over
Bonjour to connect TO Leopard machines (including connecting between
the two Leopard machines on the LAN. Either machine can connect to
the remaining Tiger machine. (Which is good enough with respect to
that machine: I just have to remember to create a session on the
Leopard machine so that I can transmit the bit of data from the Tiger
machine. This was true in 10.5.0 and remains so in 10.5.1.

Today I started looking into the matter. Part of the problem is the
inherited ipfw firewall on my Mini (the Mini was upgraded to Leopard
via Erase and Install plus Migration Assistant), and had an ipfw
firewall built using Flying Buttress while it was running Tiger.

However, the Macbook had no ipfw firewall beyond the seemingly always
present rule
   65535 all ip from any to any
which doesn't block "much".

On the Macbook, the incoming Bonjour iChat connections were being
blocked by the Application firewall. The machine was set to "Set
access for specific services and applications" and both iChat and
iChatAgent were in the list of apps and services and set to Allow.
(That is also true on the Mini, but the ipfw firewall makes it moot.)

I was able to make iChat connections over Bonjour to the Macbook by
temporarily setting the firewall to "Allow all incoming connections".
I don't mind doing that when I'm behind a NAT router and connected
only to machines I control. So now I can make all the connections I
need.

I'm close to concluding that the right way--for those with sufficient
skill--to manage the Leopard firewall is to set it to "Allow all
incoming connections" and use WaterRoof <http://www.hanynet.com/waterroof/
 > to build a suitable ipfw firewall.

   --John



Mark as Read
  OutlineAll MessagesOlder MessagesOldest MessagesNewest MessagesNewer Messages

(No messages yet. Post a message.)

  OutlineAll MessagesOlder MessagesOldest MessagesNewest MessagesNewer Messages


 [F] TidBITS  / TidBITS  / TidBITS Talk  / Leopard firewall vs iChat over Bonjour




Add a message

To add a message to this discussion, you must be a registered user. Enter your email address below. If you have an account associated with the email address you enter, you will be prompted for your password. If not, you'll be able to create a new account with no fuss.

Enter your email address:

Submit