Re: per-interface packet filters

From: Andre Oppermann (andre_at_freebsd.org)
Date: 12/14/04

  • Next message: Andre Oppermann: "Re: per-interface packet filters"
    Date: Tue, 14 Dec 2004 13:54:25 +0100
    To: vova@fbsd.ru
    
    

    Vladimir Grebenschikov wrote:
    >
    > В вт, 14/12/2004 в 11:51 +0300, Gleb Smirnoff пишет:
    >
    > > I know this. We have a well commented firewall scripts, we store them at RCS,
    > > we do many things to make our life easier. But my practice (and my collegues)
    > > shows that per interface filters are easier to understand and maintain when
    > > number of interfaces grows up to 20 and more, and they all are logically
    > > different - clients, servers, DMZs, hardware, nated networks, etc.
    > >
    > > Again, this feature is not for all. This is for people who build complicated
    > > routers on FreeBSD. It is not going to hurt standard host setups.
    >
    > Frankly speaking, I think ppl who runs real-life router with firewall on
    > fbsd will vote for this feature by both hands.
    >
    > I sometime, some years ago I had freebsd router with near to 100
    > interfaces (mostly VLANs and FrameRelay customers connections, and
    > about 10 physical media interfaces). This router transfers some
    > thousands packets per second. It was real trouble to rearrange ipfw
    > table with large (very large) number of jumps (especially in case when
    > some number range was exceeded and renumbering required). Also most of
    > router interrupt time was spent in going through client multiplexer part
    > of ipfw ruleset.
    >
    > Gleb, please do the feature.
    >
    > Why we do not avoid bottlenecks where they can be avoided ?
    > With that feature we can select right rules for specific interface
    > without do linear search by ruleset.

    It's about HOW to implement it. I think the ways proposed so far are
    hackish, too complex and outside of our framework which was very well
    designed and allows this kind of feature without any of the hacks and
    extentions discussed here.

    We have to properly DESIGN these feature instead of just hacking them
    in.

    > Do we what FreeBSD be used on large scale of setups or we have think
    > targeting ?

    As long as there is a sufficient large base we are not opposed to it.
    What we are opposed at is tradeoffs which favor one particular minority
    special interest over the general average interest set.

    > -- off-topic --
    > Days ago FreeBSD was only OS flexible and stable enough to be use in
    > complex, customized network environments, but now-days it is not so :(,
    > and you know why.
    > -- off-topic -- (not for flame or advocacy, just emotion)

    No, I don't know why and this isn't helping any.

    -- 
    Andre
    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"
    

  • Next message: Andre Oppermann: "Re: per-interface packet filters"

    Relevant Pages

    • Re: Problems with port forwarding to IIS behind a router
      ... server or DNS Error ... It won't work from inside your router - it'll only ... It's a feature of most routers - packets ... received on an interface will not be sent back to the same interface, ...
      (microsoft.public.windowsxp.network_web)
    • [Full-Disclosure] FW: Cisco Vulnerability forensic protocol analysis results.
      ... AMILABS CISCO IP PROTOCOL EXPLOIT TESTING RESULTS ... Cisco router interfaces using either all or one of the following IP ... of a remote Cisco interface uses all of them. ... output buffer failures, 0 output buffers swapped out Router4# ...
      (Full-Disclosure)
    • Re: Site-to-Site VPN client routing question - clients at branch office not able to acce
      ... I would recommend that you use some other machine as your router, ... select the demand-dial interface from the dropdown list. ... On the RRAS server in Shanghai, configure a demand-dial interface and give it a static route to 194.1.1.0/24 as above. ... This makes sure that the connection is made to the correct dd interface and sets up the correct route back to Shanghai through the VPN link. ...
      (microsoft.public.windows.server.networking)
    • Point to Point T1 with Cisco 1841 Routers
      ... checked it in the morning and on my side, the router had a lot of CRC ... interface FastEthernet0/0 ... ip http access-class 23 ... minute output rate 0 bits/sec, 0 packets/sec ...
      (comp.dcom.sys.cisco)
    • Re: moved a working network, now it doesnt work
      ... router I can ping the internet with no problem. ... From one of your Linux machines can you ping the FA 0/1 interface (default ... are NOT natting so if CAN ping from the router, ...
      (comp.dcom.sys.cisco)