From owner-freebsd-questions@FreeBSD.ORG Wed Jun 16 07:56:45 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id D13DC16A4CE for ; Wed, 16 Jun 2004 07:56:45 +0000 (GMT) Received: from ms-smtp-02.nyroc.rr.com (ms-smtp-02.nyroc.rr.com [24.24.2.56]) by mx1.FreeBSD.org (Postfix) with ESMTP id 7AB5C43D39 for ; Wed, 16 Jun 2004 07:56:45 +0000 (GMT) (envelope-from kevin@curranfamilynet.net) Received: from fluffy.homenet.curranfamilynet (roc-66-67-206-125.rochester.rr.com [66.67.206.125]) by ms-smtp-02 (8.12.10/8.12.10) with ESMTP id i5F1D89o017826 for ; Mon, 14 Jun 2004 21:13:08 -0400 (EDT) Received: from tower.homenet.curranfamilynet (IDENT:1000@tower.homenet.curranfamilynet [192.168.1.2]) i5F1C6ZE069976 for ; Mon, 14 Jun 2004 21:12:07 -0400 (EDT) (envelope-from kevin@curranfamilynet.net) From: Kevin Curran To: freebsd-questions@freebsd.org Content-Type: text/plain Content-Transfer-Encoding: 7bit X-Mailer: Ximian Evolution 1.0.7 Date: 14 Jun 2004 21:12:06 -0400 Message-Id: <1087261927.5494.11.camel@tower> Mime-Version: 1.0 X-Virus-Scanned: Symantec AntiVirus Scan Engine Subject: Are 4 IPFW rules enough? X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 16 Jun 2004 07:56:45 -0000 I have a cable modem and I'm using 4.9 as a NAT router for my home network. I have 4 rules in my ipfw config. The first enables NAT and the last is 65000 allow any to any. In between I ha 2 rules to deny access to ports 53 and 110 on the Internet side. That's all. Here's my thinking: I use inetd.conf to enable only the services I want, therefore the ports on which those services are listening I would want open. The two other ports I want to filter on the WAN side are filtered by the rules above. All the other ports are closed, anyway, so why spend time debugging an elaborate rule set?