From owner-freebsd-questions@FreeBSD.ORG Thu Oct 30 23:39:36 2008 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id E9B2F1065670 for ; Thu, 30 Oct 2008 23:39:36 +0000 (UTC) (envelope-from jdc@koitsu.dyndns.org) Received: from QMTA01.westchester.pa.mail.comcast.net (qmta01.westchester.pa.mail.comcast.net [76.96.62.16]) by mx1.freebsd.org (Postfix) with ESMTP id 938F58FC2F for ; Thu, 30 Oct 2008 23:39:36 +0000 (UTC) (envelope-from jdc@koitsu.dyndns.org) Received: from OMTA03.westchester.pa.mail.comcast.net ([76.96.62.27]) by QMTA01.westchester.pa.mail.comcast.net with comcast id Z5LX1a00E0bG4ec51Bfcmh; Thu, 30 Oct 2008 23:39:36 +0000 Received: from koitsu.dyndns.org ([69.181.141.110]) by OMTA03.westchester.pa.mail.comcast.net with comcast id ZBfZ1a00j2P6wsM3PBfaoV; Thu, 30 Oct 2008 23:39:34 +0000 X-Authority-Analysis: v=1.0 c=1 a=QycZ5dHgAAAA:8 a=6j5fiisGW9BtMl6RamgA:9 a=3m5H0iGkaIh8PJ7gys2cR2LyTMYA:4 a=EoioJ0NPDVgA:10 a=LY0hPdMaydYA:10 Received: by icarus.home.lan (Postfix, from userid 1000) id 9F237C9419; Thu, 30 Oct 2008 16:39:33 -0700 (PDT) Date: Thu, 30 Oct 2008 16:39:33 -0700 From: Jeremy Chadwick To: Jack Barnett Message-ID: <20081030233933.GB16747@icarus.home.lan> References: <367168.61424.qm@web56806.mail.re3.yahoo.com> <490A4487.8020101@gmail.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <490A4487.8020101@gmail.com> User-Agent: Mutt/1.5.18 (2008-05-17) Cc: mdh_lists@yahoo.com, Freebsd questions Subject: Re: Firewalls in FreeBSD? X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 30 Oct 2008 23:39:37 -0000 On Thu, Oct 30, 2008 at 06:34:31PM -0500, Jack Barnett wrote: > > Ok, I had some progress with this last night. Basically what I do is: > > in natd - redirect_port 1000 to 10000 to the internal windows box. > set ipfw to "open" file wall. > > Obviously this isn't prefect - but gives some idea of what's going on. > > What I'd like to do, is a) keep the nat redirects since that works > pretty well. > b) in ipfw, ONLY allow data back on these ports IF the windows box has > established the connection out first then deny everything else. This is called "port triggering" in the residential router world. I don't know how to do this on FreeBSD. -- | Jeremy Chadwick jdc at parodius.com | | Parodius Networking http://www.parodius.com/ | | UNIX Systems Administrator Mountain View, CA, USA | | Making life hard for others since 1977. PGP: 4BD6C0CB |