From owner-freebsd-questions@FreeBSD.ORG Sat Nov 29 07:05:20 2003 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id D2CDD16A4CE for ; Sat, 29 Nov 2003 07:05:20 -0800 (PST) Received: from smtp08.wxs.nl (smtp08.wxs.nl [195.121.6.40]) by mx1.FreeBSD.org (Postfix) with ESMTP id 8454D43F85 for ; Sat, 29 Nov 2003 07:05:19 -0800 (PST) (envelope-from akruijff@www.kruijff.org) Received: from kruij557.speed.planet.nl (ipd50a97ba.speed.planet.nl [213.10.151.186])18questions@freebsd.org; Sat, 29 Nov 2003 16:03:00 +0100 (MET) Received: from Alex.lan (localhost [127.0.0.1]) by kruij557.speed.planet.nl (8.12.9p2/8.12.9) with ESMTP id hATF4icP008984; Sat, 29 Nov 2003 16:04:44 +0100 (CET envelope-from akruijff@Alex.lan) Received: (from akruijff@localhost) by Alex.lan (8.12.9p2/8.12.9/Submit) id hATF4g6f008983; Sat, 29 Nov 2003 16:04:42 +0100 (CET envelope-from akruijff) Date: Sat, 29 Nov 2003 16:04:42 +0100 From: Alex de Kruijff In-reply-to: <1070087352.2416.100.camel@wolverine.home.net> To: Khairil Yusof Message-id: <20031129150442.GA8823@dds.nl> MIME-version: 1.0 Content-type: text/plain; charset=us-ascii Content-transfer-encoding: 7BIT Content-disposition: inline User-Agent: Mutt/1.4.1i References: <1070026625.16777.115.camel@wolverine.home.net> <20031128224536.GB815@dds.nl> <1070087352.2416.100.camel@wolverine.home.net> cc: questions@freebsd.org Subject: Re: ipfw pipes + firewall X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 29 Nov 2003 15:05:20 -0000 On Sat, Nov 29, 2003 at 02:29:13PM +0800, Khairil Yusof wrote: > On Sat, 2003-11-29 at 06:45, Alex de Kruijff wrote: > > > > 00100 83 11350 pipe 1 ip from any to any out > > > 00200 93 11266 pipe 2 ip from any to any in > > > 00300 0 0 check-state > > > 00400 0 0 deny tcp from any to any established > > > 01400 103 14855 allow tcp from any to me dst-port 22 in setup keep-state > > > ... more firewall rules which are being matched > > > I find your 400 rule very strage. Rule 400 souldn't apply because they > > are passed by 300 (this one doens't have a counter :( ). > > I'm following the example given by ipfw(8). Rule 0400 is apparently > supposed to block any non dynamic rules. Does rule 300 have a counter? > I've followed both ipfw(8) and > http://www.freebsd.org/doc/en_US.ISO8859-1/articles/dialup-firewall/rules.html Maybe i missed it but i didn't see rule 400. As you can see from the output it doesn't seem to do anything. That means it only takes up process time. I did see dst-port. Sorry for the confusion. I suppose that it being filled in for me; it not needed to write it down. > I"m using the example from the article for my pppoe connection at home. > > > For rule 1400 the dst-port is wronly placed. Port are (or can be) given > > after the ip without any marker. I would replace 1400 with: > > allow tcp from any to me 22 in > > allow tcp from me 22 to any out > > No need to have dynamic rules here so place it before 300 > > This sounds right, it would cut down on overhead of additional dynamic > rules. So making public ports rules without dynamic rules is better? No you use both. Dynamic rules are use so the computer seem unreacable from the out site (i.e. ftp, web, ect. server can not be reaced) and seems fully open from the inside (i.e. allowing you to surf the web). > Digging in the archives, Matthew Seaman said that dynamic rules should > be safer, but I'm not sure if it applies for my case. > > I'm no security expert, so thanks for the insight. This is how i would setup a basic firewall: 1 Reject spoofing out 2 Deny spoofing in 3 Allow wanted incomming traffic (and out again) (let say you like to ssh your computer from the internet or to have visitors to you website) 4 check-state 5 Allow traffic out and keep-state 6 Reject everyting out (proberbly doesn't gets any hits because of 5) 7 Deny everyting else -- Alex Articles based on solutions that I use: http://www.kruijff.org/alex/index.php?dir=docs/FreeBSD/