RE: Application layer firewall on FreeBSD, is it possible ?

From: Daniel Dvoøák (dandee_at_hellteam.net)
Date: 08/31/05

  • Next message: Beecher Rintoul: "Re: More "make release" problems"
    To: "'Charles Swiger'" <cswiger@mac.com>, <dandee@volny.cz>
    Date: Wed, 31 Aug 2005 02:14:56 +0200
    
    

    Okay, thank you for advise. Maybe I did not understand fully but ...

    ... but you know, proxy is not what I am asking, proxy is not firewall.

    We do not need to restrict everything and all members.

    We like full routeable network with full access to IPv6 / IPv4 internet
    without any necessary action like configure proxy clients at all pc´s our
    members.

    We only want to deny only p2p applications by default for all pc´s
    regardless of used protocol/ports and to allow grantting access to p2p
    networks each members in individual way, because we have to prevent another
    letter from our ISP which was contacted by BSA that from our public IP (
    from one member in private ip space ) ... traffic ... share ... violate ...
    authorial law.

    So of course it must be combination of IP and application osi model
    firewall.

    Gateway server should check all packets and their contents to decide if
    allowed or denied in fast way like l7-filter on Linux OS.

    So is it possible on FreeBSD OS ?

    Thanks

    Since my question here is not right like somebody told me, this is last
    e-mail in this mailling list for this theme, and I send it to
    freebsd-question, freebsd-ipfw and freebsd-pf mailling lists.

    Dan

    -----Original Message-----
    From: owner-freebsd-current@freebsd.org
    [mailto:owner-freebsd-current@freebsd.org] On Behalf Of Charles Swiger
    Sent: Tuesday, August 30, 2005 9:51 PM
    To: dandee@volny.cz
    Cc: freebsd-current@freebsd.org
    Subject: Re: Application layer firewall on FreeBSD, is it possible ?

    On Aug 30, 2005, at 2:58 PM, Daniel Dvoøák wrote:
    > let me ask you for task "how to control p2p applications and their
    > traffic with dynamic ports from user´s commputers on gateway".
    >
    > We are small wireless community and have shared access to internet for
    > all members. Core members decided to control p2p traffic by default
    > and to allow each person in individual way, after showing their
    > knowledge of authorial low. :)
    >
    > But since many dc hubs, edonkey servers, bittorents web trackers and
    > so on use dynamic not standard ports, how to control it ?

    Start with a "deny all" policy, and use L7 proxies like squid for the
    specific protocols like HTTP which you want to permit. If you're really
    serious about controlling the traffic, don't let your router talk to
    anything but your proxy server in order to be certain that the client
    machines have to go through that.

    --
    -Chuck
    _______________________________________________
    freebsd-current@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-current
    To unsubscribe, send any mail to "freebsd-current-unsubscribe@freebsd.org"
    _______________________________________________
    freebsd-current@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-current
    To unsubscribe, send any mail to "freebsd-current-unsubscribe@freebsd.org"
    

  • Next message: Beecher Rintoul: "Re: More "make release" problems"

    Relevant Pages

    • RE: Application layer firewall on FreeBSD, is it possible ?
      ... but you know, proxy is not what I am asking, proxy is not firewall. ... > We do not need to restrict everything and all members. ... > regardless of used protocol/ports and to allow grantting access to p2p ... > anything but your proxy server in order to be certain that the client ...
      (freebsd-current)
    • Re: tproxy on freebsd
      ... with pf+proxy on FreeBSD gateways without any problems... ... i could use a sample configuration file ... FYI i already running transparent proxy with ipf+ipnat,: ... debian v3.4 and ms window 2003 server/professional). ...
      (freebsd-stable)
    • FW: Application layer firewall on FreeBSD, is it possible ?
      ... but you know, proxy is not what I am asking, proxy is not firewall. ... We do not need to restrict everything and all members. ... Core members decided to control p2p traffic by default and to allow ...
      (freebsd-questions)
    • Re: Connection via proxy
      ... > MM> browser to connect via the internet via a proxy ... > MM> up the internet connection for a the Windows ... > MM> FreeBSD side of my laptop. ... > MM> that mozilla can not find the proxy server. ...
      (freebsd-questions)
    • FreeBSD Firewall Questions: (Regular) Packet Filtering vs. Stateful Packet Filtering vs. Dynamic Pro
      ... the problem is - i want to use freebsd as a gateway/router/firewall ... web services= packet filtering at application level ... -adaptive proxy filtering is safer than the above two, ... can freebsd be setup to run netfilter (linux package - if linux ...
      (comp.security.firewalls)