DHCP and the "SIMPLE" option in /etc/rc.firewall

From: James A. Coulter (james.coulter_at_cox.net)
Date: 07/30/04

  • Next message: Peter Ryan: "RE: backspace and delete keys behavior"
    To: <freebsd-questions@freebsd.org>
    Date: Fri, 30 Jul 2004 07:58:51 -0500
    
    

    I am setting up a firewall for a gateway/router running FreeBSD 4.10.

    This is for a small home LAN.

    I have already compiled and installed a custom kernel with the IPFIREWALL
    and IPDIVERT options and configured the firewall to pass any to any without
    any problems - now it's time to start locking it down.

    I would like to use the firewall_type="SIMPLE" option rc.conf. But I'm not
    sure how I should set up my external nic in /etc/rc.firewall, i.e:

    # set these to your outside interface network and netmask and ip
            oif="ed0"
            onet="192.0.2.0"
            omask="255.255.255.240"
            oip="192.0.2.1"

    My outside interface is connected to a cable modem and is configured for
    DHCP

    Without a static IP address for my outside interface, how do I set these
    options?

    TIA for your help.

    Jim C.

    -----------------------------------
    Check it out: The Black Dog Gallery
    http://polaris.umuc.edu/~jcoulter
     

    _______________________________________________
    freebsd-questions@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-questions
    To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org"


  • Next message: Peter Ryan: "RE: backspace and delete keys behavior"

    Relevant Pages

    • RE: DHCP and the "SIMPLE" option in /etc/rc.firewall
      ... > The handbook Firewall section has been rewritten. ... > the FreeBSD install when 5.x ever makes it to the stable branch. ... > the IPFIREWALL and IPDIVERT options and configured the ... > My outside interface is connected to a cable modem and is ...
      (freebsd-questions)
    • Re: ftp problem
      ... > here is my whole firewall script ... > # No restrictions on Loopback Interface ... > # or from this gateway server destine for the public Internet. ... > # Allow out secure FTP, Telnet, and SCP ...
      (freebsd-questions)
    • Re: Checkpoint experiences
      ... decide they want the firewall used by the big boys...often repeated, ... The Nokia appliance IPSO, is useful if you don't want to take the ... It is no wonder that the Nokia interface is called ... > billions on training, and classes, consultants, support contracts, etc. ...
      (comp.security.firewalls)
    • Re: Lets talk about firewalls - what do we as a group think a firewall should be/have?
      ... part of the same network as the LAN. ... Each interface of a firewall should be distinct from ... interfaces, so a "DMZ interface" is not a requirement. ...
      (comp.security.firewalls)
    • Proxy ARP and Routing
      ... some CPE from our ISP connected to a firewall. ... the public IPs on the physical DMZ network. ... packets to the host on the DMZ? ... on the DMZ interface. ...
      (SunManagers)