From owner-freebsd-questions@FreeBSD.ORG Sat Jul 1 16:41:47 2006 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 45F3316A494 for ; Sat, 1 Jul 2006 16:41:47 +0000 (UTC) (envelope-from freebsd.ph@gmail.com) Received: from wr-out-0506.google.com (wr-out-0506.google.com [64.233.184.232]) by mx1.FreeBSD.org (Postfix) with ESMTP id F3F6B44B06 for ; Sat, 1 Jul 2006 15:46:42 +0000 (GMT) (envelope-from freebsd.ph@gmail.com) Received: by wr-out-0506.google.com with SMTP id i34so398688wra for ; Sat, 01 Jul 2006 08:46:42 -0700 (PDT) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:mime-version:content-type; b=G5tGqscgrtjzYkzDGeEDptEAjl3fOmsxik86Kk1FFvoku274eApK1p41HiQV8r6d7mTQVIRmOSoc20Gafpo0C9HATNl6/Kp+pJ4xmq9ZPpht07sRYSAcyLIK6mI3h14nEDNs78wKM2t6pBAcWeCy3PFeymGOu9CBjXYlcn62dQQ= Received: by 10.54.148.3 with SMTP id v3mr2012788wrd; Sat, 01 Jul 2006 08:46:42 -0700 (PDT) Received: by 10.54.122.11 with HTTP; Sat, 1 Jul 2006 08:46:42 -0700 (PDT) Message-ID: Date: Sat, 1 Jul 2006 23:46:42 +0800 From: "jan gestre" To: freebsd-questions@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Content-Disposition: inline X-Content-Filtered-By: Mailman/MimeDel 2.1.5 Subject: pf on freebsd 6.1 on DMZ in m0n0wall question X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 01 Jul 2006 16:41:47 -0000 hi to all, i recently installed and configured (postfix+dovecot+amavisd-new+clamav+dspam+roundcubemail) in my freebsd 6.1box, i placed the box in my dmz protected by m0n0wall, however i have no firewall on the mentioned box and i'm relying on m0n0wall to protect it. is that ok? i'm new to freebsd and read about pf and i'm having some thoughts of installing pf as firewall in my webmailserver but i'm afraid to mess things up especially now that the box is already a production server, do i really need to install a separate firewall? is it an overkill? if not then anybody kind enough to lend a working pf configuration that allows http, smtp and ssh, i've read the handbook but don't understand it much particularly the firewall thing. TIA