RE: DHCP and the "SIMPLE" option in /etc/rc.firewall

From: James A. Coulter (james.coulter_at_cox.net)
Date: 07/30/04

  • Next message: James A. Coulter: "Firewall Rule Set not allowing access to DNS servers?"
    To: <Barbish3@adelphia.net>
    Date: Fri, 30 Jul 2004 09:35:31 -0500
    
    

    Thanks - I'm going to give the Stateful + NATD rule set a try.

    > -----Original Message-----
    > From: owner-freebsd-questions@freebsd.org
    > [mailto:owner-freebsd-questions@freebsd.org] On Behalf Of JJB
    > Sent: Friday, July 30, 2004 8:20 AM
    > To: James A. Coulter; freebsd-questions@freebsd.org
    > Subject: RE: DHCP and the "SIMPLE" option in /etc/rc.firewall
    >
    >
    > The handbook Firewall section has been rewritten.
    >
    > It's temporally available from www.a1poweruser.com/FBSD_firewall/
    > as the Doc group works to sanitize the English.
    > It incorporates the long awaited solution to
    > getting ipfw + natd + stateful rules to function together,
    > as well as OpenBSD pf firewall which is scheduled to become
    > the third built in firewall software solution delivered with
    > the FreeBSD install when 5.x ever makes it to the stable branch.
    >
    >
    >
    > -----Original Message-----
    > From: owner-freebsd-questions@freebsd.org
    > [mailto:owner-freebsd-questions@freebsd.org]On Behalf Of
    > James A. Coulter
    > Sent: Friday, July 30, 2004 8:59 AM
    > To: freebsd-questions@freebsd.org
    > Subject: DHCP and the "SIMPLE" option in /etc/rc.firewall
    >
    > I am setting up a firewall for a gateway/router running FreeBSD 4.10.
    >
    > This is for a small home LAN.
    >
    > I have already compiled and installed a custom kernel with
    > the IPFIREWALL and IPDIVERT options and configured the
    > firewall to pass any to any without any problems - now it's
    > time to start locking it down.
    >
    > I would like to use the firewall_type="SIMPLE" option
    > rc.conf. But I'm not sure how I should set up my external
    > nic in /etc/rc.firewall, i.e:
    >
    > # set these to your outside interface network and netmask and ip
    > oif="ed0"
    > onet="192.0.2.0"
    > omask="255.255.255.240"
    > oip="192.0.2.1"
    >
    > My outside interface is connected to a cable modem and is
    > configured for DHCP
    >
    > Without a static IP address for my outside interface, how do
    > I set these options?
    >
    > TIA for your help.
    >
    > Jim C.
    >
    > -----------------------------------
    > Check it out: The Black Dog Gallery http://polaris.umuc.edu/~jcoulter

    _______________________________________________
    freebsd-questions@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-questions
    To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org"


  • Next message: James A. Coulter: "Firewall Rule Set not allowing access to DNS servers?"

    Relevant Pages

    • Re: ftp problem
      ... > here is my whole firewall script ... > # No restrictions on Loopback Interface ... > # or from this gateway server destine for the public Internet. ... > # Allow out secure FTP, Telnet, and SCP ...
      (freebsd-questions)
    • Re: Checkpoint experiences
      ... decide they want the firewall used by the big boys...often repeated, ... The Nokia appliance IPSO, is useful if you don't want to take the ... It is no wonder that the Nokia interface is called ... > billions on training, and classes, consultants, support contracts, etc. ...
      (comp.security.firewalls)
    • Re: Lets talk about firewalls - what do we as a group think a firewall should be/have?
      ... part of the same network as the LAN. ... Each interface of a firewall should be distinct from ... interfaces, so a "DMZ interface" is not a requirement. ...
      (comp.security.firewalls)
    • Proxy ARP and Routing
      ... some CPE from our ISP connected to a firewall. ... the public IPs on the physical DMZ network. ... packets to the host on the DMZ? ... on the DMZ interface. ...
      (SunManagers)
    • RE: [fw-wiz] Dynamic routing on a firewall
      ... is on this interface", rather than having to work it out manually each time. ... Obviously, if the firewall is using dynamic routing, there would be no ... >> party is in their own DMZ. ...
      (Firewall-Wizards)