From owner-freebsd-questions Wed Jan 9 4:25:29 2002 Delivered-To: freebsd-questions@freebsd.org Received: from relay1.ntu-kpi.kiev.ua (www.ntu-kpi.kiev.ua [212.111.192.161]) by hub.freebsd.org (Postfix) with ESMTP id AF65337B41C for ; Wed, 9 Jan 2002 04:25:21 -0800 (PST) Received: from comsys.ntu-kpi.kiev.ua (eth0.comsys.ntu-kpi.kiev.ua [10.0.1.184]) by relay1.ntu-kpi.kiev.ua (Postfix) with ESMTP id 7181E2F0E8; Wed, 9 Jan 2002 14:25:17 +0200 (EET) Received: from pm5149 (pm514-9.comsys.ntu-kpi.kiev.ua [10.18.54.109]) by comsys.ntu-kpi.kiev.ua (8.11.6/8.11.6) with SMTP id g09CRUF74572; Wed, 9 Jan 2002 14:27:30 +0200 (EET) Message-ID: <005501c198ff$8fac4a00$6d36120a@comsys.ntukpi.kiev.ua> From: "Andrey Simonenko" To: "Heimes, Rene" Cc: References: Subject: Re: firewalling with ipfw Date: Wed, 9 Jan 2002 14:19:52 +0300 MIME-Version: 1.0 Content-Type: text/plain; charset="koi8-r" Content-Transfer-Encoding: 8bit X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 5.00.2014.211 X-MimeOLE: Produced By Microsoft MimeOLE V5.00.2014.211 Sender: owner-freebsd-questions@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG ----- Original Message ----- From: Heimes, Rene Newsgroups: lucky.freebsd.questions Sent: Wednesday, January 09, 2002 3:07 PM Subject: AW: firewalling with ipfw > >IP Filter also can't do it for you. Probably you should tell us your > task, > >because I can't understand really needs of such Firewall feature. > > OK, letīs try... > There is one half Class-C Network (out of 16 others....) > There are a several groups of servers and workstations with different > inbound/ outbound rulesets: > - Webservers > - Application Servers > - Full Access Workstations > - Restricted Access Workstations and finally > - No Access Workstations > > Each group matches to non-coherent IP-Addresses. > > Right now, because i wrote each ruleset for almost every single ip, > there is a 70k large rc.firewall file that affects system throughput > heavily. > > Thatīs my problem - understandable now? How can i make this file > smaller? How can i aggregate rulesets and ipīs??? > 1. Use "keep-state" 2. Use "skipto" 3. Use intermediate FreeBSD routers for IP Firewalling 4. Reorganize structure of your IP addresses space 5. Restrict access with hardware routers To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-questions" in the body of the message