firewalling policy

From: VA (listat_at_synty.net)
Date: 02/19/04

  • Next message: Felipe Neuwald: "Re: firewalling policy"
    Date: Thu, 19 Feb 2004 14:54:07 +0200 (EET)
    To: freebsd-isp@freebsd.org
    
    

    Hi fellow SysAdmins,

    I'm building a FreeBSD route/firewall for a little heavier use. I will use
    pf for firewall because it's more familiar and since I need to maintain a
    few OpenBSD boxes as well.

    Anyways I was hoping to get an opinion for a firewall rule structure.
    There are 10 physical NICs (Intel Dual 100Mbs) and also a bunch of VLANs.

    What is the best point to firewall? Naturally default block strategy
    assumed. I know each interface need rules to achieve good security, but
    what about external interface (WAN
    link)? Is it safe just to firewall each internal interface, because
    otherwise I need "double rules" and it get's more complicated.

    Any other hints to give or good optimized examples for pf in larger
    enviroment? I will surely make a public document once I get this up and
    running.
    Thanks in advance and specially all you developers of this great OS!

    -Vesa, SysAdmin, Finland
    _______________________________________________
    freebsd-isp@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-isp
    To unsubscribe, send any mail to "freebsd-isp-unsubscribe@freebsd.org"


  • Next message: Felipe Neuwald: "Re: firewalling policy"

    Relevant Pages

    • Re: ftp problem
      ... > here is my whole firewall script ... > # No restrictions on Loopback Interface ... > # or from this gateway server destine for the public Internet. ... > # Allow out secure FTP, Telnet, and SCP ...
      (freebsd-questions)
    • Re: Checkpoint experiences
      ... decide they want the firewall used by the big boys...often repeated, ... The Nokia appliance IPSO, is useful if you don't want to take the ... It is no wonder that the Nokia interface is called ... > billions on training, and classes, consultants, support contracts, etc. ...
      (comp.security.firewalls)
    • Re: Lets talk about firewalls - what do we as a group think a firewall should be/have?
      ... part of the same network as the LAN. ... Each interface of a firewall should be distinct from ... interfaces, so a "DMZ interface" is not a requirement. ...
      (comp.security.firewalls)
    • Proxy ARP and Routing
      ... some CPE from our ISP connected to a firewall. ... the public IPs on the physical DMZ network. ... packets to the host on the DMZ? ... on the DMZ interface. ...
      (SunManagers)
    • RE: [fw-wiz] Dynamic routing on a firewall
      ... is on this interface", rather than having to work it out manually each time. ... Obviously, if the firewall is using dynamic routing, there would be no ... >> party is in their own DMZ. ...
      (Firewall-Wizards)