Re: Firewalls and Webmin

From: Kevin Kinsey (kdk_at_daleco.biz)
Date: 02/17/05

  • Next message: perikillo: "Re: Newbie Question; security logs"
    Date: Wed, 16 Feb 2005 18:13:52 -0600
    To: Alex D'Elia <alex@fan.priv.at>
    
    

    Alex D'Elia wrote:

    >Hi SigmaX,
    >
    >* SigmaX <scottclansman@cwazy.co.uk> [050217 17:45]:
    >
    >
    >
    >>Heya;
    >>I have FreeBSD 5.3 and need to set up the firewall. I've never done
    >>anything with Firewall on a *NIX system without the help of Webmin, and
    >>I'm new to BSD in general. Webmin gives me an error when trying to use
    >>the BSD Firewall module.
    >>
    >>I tried doing "ipfw sh" to see what was up, and I get "ipfw:
    >>getsockopt(IP_FW_GET): Protocol not available"
    >>
    >>I found a post from a while back that said I need to recompile my
    >>kernel. I can't imagine that that's the case for a firewall in
    >>general. I need a firewall... if I can't use Webmin (read: ipfw) I'm
    >>gonna need a REALLY good howto :-P. Any help?
    >>
    >>
    >>
    >
    >
    >first of all I say ( as someone else will do ) that you should post
    >technical questions to freebsd-questions because this is a list of
    >discussion about FreeBSD and not about technical problems.
    >But I can tell you that if you follow the instructions of the
    >handbook, you will for sure have enough informations to get you going.
    >The handbook its a really good documentation, not only for FreeBSD
    >but for a lot more ;^)
    >
    >
    >

    Yes, and it should have been consulted prior to this posting. I
    don't mean to directly offend, but you have made at least one
    mistake in your advice. Likely I will, too; and, SigmaX, this is
    why your question is on the wrong forum.

    >And Yes, you need to recompile the kernel if you want to use your
    >system for a firewalling purpose.
    >
    >

    Not if he's using 5.3 and doesn't want NAT. From the Handbook:

      "IPFW is included in the basic FreeBSD install as a separate run time
      loadable module. IPFW will dynamically load the kernel module when
       the rc.conf statement firewall_enable="YES" is used. You do not need
      to compile IPFW into the FreeBSD kernel unless you want NAT function
     enabled."

    >But that's not an hack ..... its preety easy.
    >I personally find it easyer than in linux ( with all respects ),
    >
    >
    >

    It's easy once you've done it a few times. My first time was
    rather frightening, personally, but only because *I* was freaked
    out ... the system performed admirably. And, then you need
    "mergemaster" ...

    >I already used ipfw in FreeBSD-4.X and ipf and pf with OpenBSD.
    >Now that the new STABLE BRANCH 5.3 its including the pf firewall
    >from OpenBSD, I use that, 'cause I find it really powerfull and yet
    >nice to configure.
    >
    >just take a look at the handbook, and you'll find a lot of answers
    >to your questions.
    >You find the documentation also on your system: /usr/share/doc/en/books
    >for english language documentation :)
    >
    >
    >

    Good advice there too.

    Kevin Kinsey
    _______________________________________________
    freebsd-newbies@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-newbies
    To unsubscribe, send any mail to "freebsd-newbies-unsubscribe@freebsd.org"


  • Next message: perikillo: "Re: Newbie Question; security logs"

    Relevant Pages

    • Re: bsd firewall
      ... > I want to set up an easy firewall with bsd an foolproof one. ... As to ``foolproof'', as they say, make something foolproof and the ... or the handbook or any of the nice books referred to on the FreeBSD ... You setup a firewall ``in front of'' your windows peecee, ...
      (comp.unix.bsd.freebsd.misc)
    • Re: solaris
      ... >> router while I attempted to explain the router was ... >> of handling a CLI OS like FreeBSD? ... that these individuals would not be the target market ... > despite the fact that it should include a firewall. ...
      (freebsd-questions)
    • Re: book/site recommendations for newbie with NO UNIX background?
      ... > The FreeBSD handbook has a section on Daemons,signals and killing ... Chapter 8 'Taking control' covers processes and daemons. ... When it goes to the web I will have a firewall of some kind. ...
      (comp.unix.bsd.freebsd.misc)
    • Re: Wanting To Try FreeBSD: Security Question.
      ... How hard is it to secure FreeBSD for a desktop computer? ... The relatively minimal pf.conf file for the firewall I run on my laptop, ... A firewall is not the end of all your security needs. ...
      (comp.unix.bsd.freebsd.misc)
    • Re: RX (download) limit problem
      ... > I've been seeing a strange problem with my 5.4-STABLE freebsd ... > behind it or the firewall itself) can get a decent rate. ... > In talking to some openBSD guys we had a theory that it might be something ... > the upload and download being kept symmetric and hence so low on the ...
      (freebsd-current)