Date: Mon, 10 Mar 2014 14:56:51 -0400 From: Jason Hellenthal <jhellenthal@dataix.net> To: =?utf-8?Q?Ermal_Lu=C3=A7i?= <eri@freebsd.org> Cc: Joe Nosay <superbisquit@gmail.com>, John-Mark Gurney <jmg@funkthat.com>, "freebsd-net@freebsd.org" <freebsd-net@freebsd.org> Subject: Re: Using pf.conf with public access points. Message-ID: <71CCF277-8BF7-4C3B-9F9E-2095EA4CC060@dataix.net> In-Reply-To: <CAPBZQG3jzWnLk_Ea-VwkpTg2wHCF21M4faKzsYfVDAy9SAw3mg@mail.gmail.com> References: <CA%2BWntOsQG-OeF8AmiftKt6-7upXTN7Pnv4ogZJmt6kjZ0GsZAA@mail.gmail.com> <20140309231829.GG32089@funkthat.com> <9C40270E-18E0-4993-B7C5-BD8B5A24C95D@dataix.net> <CAPBZQG3jzWnLk_Ea-VwkpTg2wHCF21M4faKzsYfVDAy9SAw3mg@mail.gmail.com>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --] I nearly forgot all about that feature thank you for the reminder. -- Jason Hellenthal Voice: 95.30.17.6/616 JJH48-ARIN > On Mar 10, 2014, at 10:20, Ermal Luçi <eri@freebsd.org> wrote: > > Usually pf(4) does support having dynamic ips inside its ruleset. > For example just putting the interface name as address or putting $iface:0 for first address etc... > > Take a look an man page of pf.conf and search for the string 'Interface names and interface group names can' > > >> On Sun, Mar 9, 2014 at 11:27 PM, Jason Hellenthal <jhellenthal@dataix.net> wrote: >> You'll want to not use up addresses in your pf.conf >> >> Block on default and then open up by definition of ports instead. Forget the whole IPAddr thing and treat this as a roaming client firewall. >> >> >> -- >> Jason Hellenthal >> Voice: 95.30.17.6/616 >> JJH48-ARIN >> >> > On Mar 9, 2014, at 19:18, John-Mark Gurney <jmg@funkthat.com> wrote: >> > >> > Joe Nosay wrote this message on Sun, Mar 09, 2014 at 15:36 -0400: >> >> 2. How do I compensate for the use of public access points when the IP >> >> addresses will always be different? >> > >> > it doesn't appear that pf has this ability, but it looks like ipfw >> > has this, from ipfw(8): >> > me matches any IP address configured on an interface in the >> > system. >> > >> > So, maybe switching to ipfw might be an option.. >> > >> > -- >> > John-Mark Gurney Voice: +1 415 225 5579 >> > >> > "All that I will do, has been done, All that I have, has not." >> > _______________________________________________ >> > freebsd-net@freebsd.org mailing list >> > http://lists.freebsd.org/mailman/listinfo/freebsd-net >> > To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org" > > > > -- > Ermal [-- Attachment #2 --] 0 *H 010 + 0 *H 90000 *H 010 UIL10U StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 1 Primary Intermediate Client CA0 130518085048Z 140519220947Z0H10Ujhellenthal@dataix.net1%0# *H jhellenthal@dataix.net0"0 *H 0 '`TmfkܨJ5u+c'Upb`zv)&ȸXZ*VN6JvLoVoh}g pQDŽKf/tZA˳("4Ԅ˻'d2h|IBl'^v^;'e8S99ۿVm|k8_UQtC"5l!kjZ]އQGn\Bh!FTsD%pV^Eӑd¨x"9 г"f 00 U0 0U0U%0++0UڔfmVʢ$䟓0U#0Sr풜\|~5NԸQ0!U0jhellenthal@dataix.net0LU C0?0;+70*0.+"http://www.startssl.com/policy.pdf0+00' StartCom Certification Authority0This certificate was issued according to the Class 1 Validation requirements of the StartCom CA policy, reliance only for the intended purpose in compliance of the relying party obligations.06U/0-0+)'%http://crl.startssl.com/crtu1-crl.crl0+009+0-http://ocsp.startssl.com/sub/class1/client/ca0B+06http://aia.startssl.com/certs/sub.class1.client.ca.crt0#U0http://www.startssl.com/0 *H {0Ӹ,52W{Ey8b[{7 _+P"n["-,@ŽpJ-W$ݍjWA-6z( RdIZ.KzXє[K6}{s+v.Qh0PͅKhTw 0I73lz*Kv4Kkگ63;p1:ױ@)]ok>:W%XwC1þL/o8~#oP0400 *H 0}10 UIL10U StartCom Ltd.1+0)U"Secure Digital Certificate Signing1)0'U StartCom Certification Authority0 071024210155Z 171024210155Z010 UIL10U StartCom Ltd.1+0)U"Secure Digital Certificate Signing1806U/StartCom Class 1 Primary Intermediate Client CA0"0 *H 0 -).2AUGo#G B|NDRpM-B=o-we5JQpa>O.#._<V [~**pz~3WG .ᘟMlr[<Ce6fqO"uxfWN#uicgkv$Lb%y`_{`xK'GN 00U00U0USr풜\|~5NԸQ0U#0N@[i04hCA0f+Z0X0'+0http://ocsp.startssl.com/ca0-+0!http://www.startssl.com/sfsca.crt0[UT0R0'%#!http://www.startssl.com/sfsca.crl0'%#!http://crl.startssl.com/sfsca.crl0U y0w0u+70f0.+"http://www.startssl.com/policy.pdf04+(http://www.startssl.com/intermediate.pdf0 *H }x,\c^#wMq}>UK/^yX֏y frMIŲB61ymQҨݬZ0&
