Re: uRPF on FreeBSD

From: Haesu (haesu_at_towardex.com)
Date: 10/03/03

  • Next message: Troy Settle: "RE: consequences of migrating to maildir storage system"
    Date: Fri, 3 Oct 2003 09:35:26 -0400
    To: Tom <tom@sdf.com>, freebsd-isp@freebsd.org
    
    

    >
    > Usually RPF is just done with ACLs (ipfw) on FreeBSD. It can be a
    > simple as have a simple input list on each interface that only permits
    > sources that are known to be on that interface. Since most systems aren't
    > running a routing protocol, so there aren't many routes and/or they don't
    > change often, it is probably the simplest way of doing this.
    >

    Yea... I hear that.. Although it'd be nice to have it on FreeBSD :)

    Even Linux has that :-/ (Though... I think Linux only does strictmode? I don't remember..)

    -hc

    -- 
    Haesu C.
    TowardEX Technologies, Inc.
    Consulting, colocation, web hosting, network design and implementation
    http://www.towardex.com | haesu@towardex.com
    Cell: (978)394-2867     | Office: (978)263-3399 Ext. 170
    Fax: (978)263-0033      | POC: HAESU-ARIN
    _______________________________________________
    freebsd-isp@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-isp
    To unsubscribe, send any mail to "freebsd-isp-unsubscribe@freebsd.org"
    

  • Next message: Troy Settle: "RE: consequences of migrating to maildir storage system"

    Relevant Pages

    • Machine doesnt boot after switching from Linux to FreeBSD
      ... I'm trying to switch a Linux system to FreeBSD. ... The full dmesg output that I get after net-booting from the rescue disk ... <PLIP network interface> on ppbus0 ... (no root path) ...
      (freebsd-questions)
    • Dummynet in an IPFilter setup
      ... I am running a FreeBSD 5.x box with IPFilter/IPNAT. ... Internet and internal interface connected to a switch for the LAN. ... I need to guarantee 128Kbit/s of the available bandwidth to the ...
      (freebsd-questions)
    • Problem with IPFilter/IPNAT
      ... I am using IPFilter and IPNat on several FreeBSD boxes. ... The LAN machines use the FreeBSD as the ... I run cache-only config. ... rl1 is external interface. ...
      (freebsd-questions)
    • Possible security issue with FreeBSD 5.4 jailing and BPF
      ... While playing around with FreeBSD 5.4 and jailing I discovered that it was ... and a BPF device is available in the jail ... "The Berkeley Packet Filter provides a raw interface to data link layers ... The ethernet interface of the host is not in promiscious mode. ...
      (Bugtraq)
    • [Full-disclosure] Possible security issue with FreeBSD 5.4 jailing and BPF
      ... While playing around with FreeBSD 5.4 and jailing I discovered that it was ... and a BPF device is available in the jail ... "The Berkeley Packet Filter provides a raw interface to data link layers ... The ethernet interface of the host is not in promiscious mode. ...
      (Full-Disclosure)