Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 8 Sep 2006 17:56:37 +0300
From:      "Mircea Popescu" <popescu.mircea@gmail.com>
To:        freebsd-pf@freebsd.org
Subject:   TRansparent firewalll (pf vs ipfw)
Message-ID:  <f51cdb70609080756t7de2b168xd632240cdc5da9ae@mail.gmail.com>

next in thread | raw e-mail | index | archive | help
Hi!

I have an Freebsd 6.0 box with a functioning bridge (bridge0 = fxp0 + rl0)

My problem is that if I try to cut access to any port on bridge0
interface using PF, nothing happens.

For example I've tried to cut access to ssh service from a certain ip
... putty still managed to get through.

The rule was:
block on bridge0 proto { tcp udp } from yy.yy.yy.yy to xx.xx.xx.xx port pppppp

BUT, with the following rule:
block on rl0 proto { tcp udp } from yy.yy.yy.yy to xx.xx.xx.xx. port pppppp

Putty couldn't obtain a connection.

Considering the fact that in linux, which I gave up using, making a
bridge would disable the interfaces within, I WOULD LIKE TO HAVE SOME
QUESTIONS ANSWERED:

1. Once the bridge0 interface is created, the fxp0 and rl0 interfaces
could still get their own ip addresses? (in linux this would be
imposible)

2. Which firewall it is more desirable to use with a bridge? PF or IPFW)


Thx a lot



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?f51cdb70609080756t7de2b168xd632240cdc5da9ae>