Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 10 Mar 2014 19:57:33 -0400
From:      Jason Hellenthal <jhellenthal@dataix.net>
To:        Joe Nosay <superbisquit@gmail.com>
Cc:        =?utf-8?Q?Ermal_Lu=C3=A7i?= <eri@freebsd.org>, "freebsd-net@freebsd.org" <freebsd-net@freebsd.org>, John-Mark Gurney <jmg@funkthat.com>
Subject:   Re: Using pf.conf with public access points.
Message-ID:  <AF2D3781-6A50-4B92-9EF3-201A5E9687F6@dataix.net>
In-Reply-To: <CA%2BWntOusW84FL0iERf=CqVJxO3cxqM86365=HVbhwhBoW9=_EA@mail.gmail.com>
References:  <CA%2BWntOsQG-OeF8AmiftKt6-7upXTN7Pnv4ogZJmt6kjZ0GsZAA@mail.gmail.com> <20140309231829.GG32089@funkthat.com> <9C40270E-18E0-4993-B7C5-BD8B5A24C95D@dataix.net> <CAPBZQG3jzWnLk_Ea-VwkpTg2wHCF21M4faKzsYfVDAy9SAw3mg@mail.gmail.com> <71CCF277-8BF7-4C3B-9F9E-2095EA4CC060@dataix.net> <CA%2BWntOusW84FL0iERf=CqVJxO3cxqM86365=HVbhwhBoW9=_EA@mail.gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
I feel as if you are over thinking this project just a little.

dhclient has nothing to do with the bssid.
wlanX can be setup to use DHCP and for wep or wpa or open connections in rc.conf.
You can't control others firewalls only your own so why the worry about that ?

-- 
 Jason Hellenthal
 Voice: 95.30.17.6/616
 JJH48-ARIN

> On Mar 10, 2014, at 16:41, Joe Nosay <superbisquit@gmail.com> wrote:
> 
> 
> 
> 
>> On Mon, Mar 10, 2014 at 2:56 PM, Jason Hellenthal <jhellenthal@dataix.net> wrote:
>> I nearly forgot all about that feature thank you for the reminder.
>> 
>> 
>> -- 
>>  Jason Hellenthal
>>  Voice: 95.30.17.6/616
>>  JJH48-ARIN
>> 
>>> On Mar 10, 2014, at 10:20, Ermal Luçi <eri@freebsd.org> wrote:
>>> 
>>> Usually pf(4) does support having dynamic ips inside its ruleset.
>>> For example just putting the interface name as address or putting $iface:0 for first address etc...
>>> 
>>> Take a look an man page of pf.conf and search for the string 'Interface names and interface group names can'
>>> 
>>> 
>>>> On Sun, Mar 9, 2014 at 11:27 PM, Jason Hellenthal <jhellenthal@dataix.net> wrote:
>>>> You'll want to not use up addresses in your pf.conf
>>>> 
>>>> Block on default and then open up by definition of ports instead. Forget the whole IPAddr thing and treat this as a roaming client firewall.
>>>> 
>>>> 
>>>> --
>>>>  Jason Hellenthal
>>>>  Voice: 95.30.17.6/616
>>>>  JJH48-ARIN
>>>> 
>>>> > On Mar 9, 2014, at 19:18, John-Mark Gurney <jmg@funkthat.com> wrote:
>>>> >
>>>> > Joe Nosay wrote this message on Sun, Mar 09, 2014 at 15:36 -0400:
>>>> >> 2. How do I compensate for the use of public access points when the IP
>>>> >> addresses will always be different?
>>>> >
>>>> > it doesn't appear that pf has this ability, but it looks like ipfw
>>>> > has this, from ipfw(8):
>>>> >             me      matches any IP address configured on an interface in the
>>>> >                     system.
>>>> >
>>>> > So, maybe switching to ipfw might be an option..
>>>> >
>>>> > --
>>>> >  John-Mark Gurney                Voice: +1 415 225 5579
>>>> >
>>>> >     "All that I will do, has been done, All that I have, has not."
>>>> > _______________________________________________
>>>> > freebsd-net@freebsd.org mailing list
>>>> > http://lists.freebsd.org/mailman/listinfo/freebsd-net
>>>> > To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"
>>> 
>>> 
>>> 
>>> -- 
>>> Ermal
> 
> 
> Has anyone thought about putting themselves in an environment similar to mine- not everything- when it comes to networking? You would have to set everything up with the following parameters:
> 1. Because you are at more than one place, you cannot setup wlanX or the wlandev in rc.conf. They must always be created after booting and logging in.
> 2. Dhclient cannot be automatic because a public access area may have more than one available bssid for connecting.
> 3. Since each public access will have different firewalls, streaming and web services may not be able to be ran.
> 4. A script would probably work better than static settings in this case.
> 
> 

[-- Attachment #2 --]
0	*H
010	+0	*H
90000
	*H
010	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 1 Primary Intermediate Client CA0
130518085048Z
140519220947Z0H10Ujhellenthal@dataix.net1%0#	*H
	jhellenthal@dataix.net0"0
	*H
0
'`TmfkܨJ5u+c'Upb`zv)&ȸXZ*VN6JvLoVoh}g
pQDŽKf/tZA˳("4Ԅ˻'d2h|IBl'^v^;'e8S99ۿVm|k8_UQtC"5l!kjZ]އQGn\BŽh!FTsD%pV^Eӑd¨x͸"9
г"f00	U00U0U%0++0UڔfmVʢ$䟓0U#0Sr풜\|~5NԸQ0!U0jhellenthal@dataix.net0LU C0?0;+70*0.+"http://www.startssl.com/policy.pdf0+00' StartCom Certification Authority0This certificate was issued according to the Class 1 Validation requirements of the StartCom CA policy, reliance only for the intended purpose in compliance of the relying party obligations.06U/0-0+)'%http://crl.startssl.com/crtu1-crl.crl0+009+0-http://ocsp.startssl.com/sub/class1/client/ca0B+06http://aia.startssl.com/certs/sub.class1.client.ca.crt0#U0http://www.startssl.com/0
	*H
{0Ӹ,52W{Ey8b[{7_+P"n["-,@ŽpJ-W$ݍjWA-6z(	RdIZ.KzXє[K6}{s+v.Qh0PͅKhTw0I73lz*Kv4Kkگ63;p1:ױ@)]ok>:W%XwC1þL/o8~#oP0400
	*H
0}10	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1)0'U StartCom Certification Authority0
071024210155Z
171024210155Z010	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 1 Primary Intermediate Client CA0"0
	*H
0
	-).2AUGo#G
B|NDRpM-B=o-we5JQpa>O.#._<V
[~**pz~3WG.ᘟMlr[<Ce6fqO"uxfWN#uicgkv$Lb%y`_{`xK'GN00U00U0USr풜\|~5NԸQ0U#0N@[i04hCA0f+Z0X0'+0http://ocsp.startssl.com/ca0-+0!http://www.startssl.com/sfsca.crt0[UT0R0'%#!http://www.startssl.com/sfsca.crl0'%#!http://crl.startssl.com/sfsca.crl0U y0w0u+70f0.+"http://www.startssl.com/policy.pdf04+(http://www.startssl.com/intermediate.pdf0
	*H

}x,\c^#wMq}>UK/^yX֏y	frMIŲB61ymQ󸟆ҨݬZ0&;@#13qۑ&	̢o	6r_;GO>*I(	74XS1r3)!LJy6Kotˆ#
_wSr
;B
ADp(fs䰷6%.W0J3:bC<8t X1<Cn=t==wST~\wkBf|15zUP)(IjVB!OfI=bb\4-*em/нSJm7N[]'@ڽD9Kr>R7/|o^I@ټ'Pa$ z9a'L)(
I}vcH]۸D*W}
m>Q|C.(,lQ000
	*H
0}10	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1)0'U StartCom Certification Authority0
060917194636Z
360917194636Z0}10	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1)0'U StartCom Certification Authority0"0
	*H
0
	lF|x{3rb6 "$^wC
d̎68#nm<r=3+/AYg}
tyL7z9RYFC҅qub4,4ǖR=3M;JK&/r5w<]&6v\t%x-0-ryF*I
cSb:̵fkt+v>mDsb;ľSV%lQ	ʿvmۿ=fVH:KߧXP8u[ClMp[)eݪ]̯1ҍ{n'fHnB?!>{
pclT\%zɢɋ,~^MXn
2n6IHi–Mi
y"H{ipz7
vOW`g:ԋr"Ɵƶ\R<*s
`z/ۣn&0݉W=+ŷv+*r3]	K߻tRKR0N0U00U0UN@[i04hCA0dU]0[0,*(&http://cert.startcom.org/sfsca-crl.crl0+)'%http://crl.startcom.org/sfsca-crl.crl0]U T0P0L+70;0/+#http://cert.startcom.org/policy.pdf05+)http://cert.startcom.org/intermediate.pdf0+00' Start Commercial (StartCom) Ltd.0Limited Liability, read the section *Legal Limitations* of the StartCom Certification Authority Policy available at http://cert.startcom.org/policy.pdf0	`HB08	`HB
+)StartCom Free SSL Certification Authority0
	*H
lf4Ѕ^}
N8^ߦ%K2;=D	[I)f%	<6+Kh9f=&9Q{~ZWpi^X
ߌE8
^Wbz)n(DÐ8<CMdE(\s{諱.\dns1:}Q;Mf{<ӚePu/CiyCFrd6%8w~kjDKx,KD4R'
]xS2݀fuٵh(a.8gd./pǖ|eCTݥ9`4ɖp,H{~k";*RKU"4N&",uJ}׸d6/#	;sIjWxřCcMw-eriG	V$yX.	~m>J9+u	U77Cb VKel$$4"}?eQ
0j
r^1o0k0010	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 1 Primary Intermediate Client CA0	+0	*H
	1	*H
0	*H
	1
140310235734Z0#	*H
	1x{U:g{:t0	+710010	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 1 Primary Intermediate Client CA0*H
	1010	UIL10U

StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 1 Primary Intermediate Client CA0
	*H
W70!o7Yg6O[b1dm,oq2w]Ɩnk&x!Ja?D$6R7Altϧ\)øL'Fat>?JVɸ Yװ,Fo
UJlDr
lExCiWHxYSm{R֒vY\Q*℥{̱쩗77MdB,@ғL_p]-{

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?AF2D3781-6A50-4B92-9EF3-201A5E9687F6>