SV: pf firewall and ftp

2012-04-16 Thread Hasse Hansson
Til: FreeBSD Questions; FreeBSD Current; FreeBSD doc Emne: Re: pf firewall and ftp Fbsd8 wrote: Running 9.0 as a gateway host with pf firewall enabled. FTP is launched by inetd. Both active and passive ftp works from lan pc's to the host ftp. The lan ftp session can be initiated from the host

Re: SV: pf firewall and ftp

2012-04-16 Thread Denny Lin
-questi...@freebsd.org] På vegne af Fbsd8 Sendt: den 16 april 2012 04:31 Til: FreeBSD Questions; FreeBSD Current; FreeBSD doc Emne: Re: pf firewall and ftp Fbsd8 wrote: Running 9.0 as a gateway host with pf firewall enabled. FTP is launched by inetd. Both active and passive ftp works from lan

Re: pf firewall and ftp

2012-04-16 Thread David Walker
There's also web available manuals for probably every release of OpenBSD here: http://www.openbsd.org/cgi-bin/man.cgi http://www.openbsd.org/cgi-bin/man.cgi?query=pf.confmanpath=OpenBSD+4.5 ___ freebsd-questions@freebsd.org mailing list

pf firewall and ftp

2012-04-15 Thread Fbsd8
Running 9.0 as a gateway host with pf firewall enabled. FTP is launched by inetd. Both active and passive ftp works from lan pc's to the host ftp. The lan ftp session can be initiated from the host or any lan pc and things work because there are no rules on the lan interface except single pass

Re: pf firewall and ftp

2012-04-15 Thread Fbsd8
Fbsd8 wrote: Running 9.0 as a gateway host with pf firewall enabled. FTP is launched by inetd. Both active and passive ftp works from lan pc's to the host ftp. The lan ftp session can be initiated from the host or any lan pc and things work because there are no rules on the lan interface except

Re: pf firewall rule numbers

2012-04-12 Thread Fbsd8
Mike Tancsa wrote: On 4/11/2012 8:34 PM, Fbsd8 wrote: In the pf log I see the rule number of the rule used to create the log file entry. pfctl -sr command does not list the rule number of each rule it lists. Hi, Try pfctl -sr -vv ---Mike Thanks the -vv printed the rule number

pf firewall rule numbers

2012-04-11 Thread Fbsd8
In the pf log I see the rule number of the rule used to create the log file entry. pfctl -sr command does not list the rule number of each rule it lists. So my question is how do I relate the rule number shown in the log listing back to the text rule file rules?

Re: pf firewall rule numbers

2012-04-11 Thread Mike Tancsa
On 4/11/2012 8:34 PM, Fbsd8 wrote: In the pf log I see the rule number of the rule used to create the log file entry. pfctl -sr command does not list the rule number of each rule it lists. Hi, Try pfctl -sr -vv ---Mike -- --- Mike Tancsa, tel +1 519 651 3400 Sentex

Re: PF firewall rules and documentation

2011-02-01 Thread Da Rock
On 02/01/11 00:40, Kevin Wilcox wrote: On Mon, Jan 31, 2011 at 05:58, Da Rock freebsd-questi...@herveybayaustralia.com.au wrote: Yes. Me unfortunately, but I did manage to pick it up quite quickly though. I had a little thief attack one of my ports and attempt login on the firewall. I had

Re: PF firewall rules and documentation

2011-01-31 Thread Patrick Lamaiziere
Le Sat, 29 Jan 2011 12:39:18 +1000, Da Rock freebsd-questi...@herveybayaustralia.com.au a écrit : I spent some time playing with pf and pf.conf, and followed the directions in the handbook. It redirected me to the openbsd site for pf.conf, and recommended it as the most comprehensive

Re: PF firewall rules and documentation

2011-01-31 Thread Da Rock
On 01/31/11 20:30, Patrick Lamaiziere wrote: Le Sat, 29 Jan 2011 12:39:18 +1000, Da Rockfreebsd-questi...@herveybayaustralia.com.au a écrit : I spent some time playing with pf and pf.conf, and followed the directions in the handbook. It redirected me to the openbsd site for pf.conf, and

Re: PF firewall rules and documentation

2011-01-31 Thread Kevin Wilcox
On Mon, Jan 31, 2011 at 05:58, Da Rock freebsd-questi...@herveybayaustralia.com.au wrote: Yes. Me unfortunately, but I did manage to pick it up quite quickly though. I had a little thief attack one of my ports and attempt login on the firewall. I had to change it to 'block in $log on $ext_if

Re: PF firewall rules and documentation

2011-01-29 Thread Da Rock
On 01/29/11 23:50, Iñigo Ortiz de Urbina wrote: I think that kind of user should never be in charge of anything security related Reading my own post I realise I forgot my question due to kiddie issues that were occuring in my vicinity. That is, how would one go about this? As for user

PF firewall rules and documentation

2011-01-28 Thread Da Rock
I spent some time playing with pf and pf.conf, and followed the directions in the handbook. It redirected me to the openbsd site for pf.conf, and recommended it as the most comprehensive documentation for pf. Firstly, I didn't find that. I had to translate the instructions into the current

PF firewall NAT and Windows IPSEC tunnel

2008-02-09 Thread Nerius Landys
Howdy folks. I have several computers behind a FreeBSD router (NAT 192.168.0.x using OpenBSD's PF) . One of those computers is a Windows machine which is using software called Cisco Systems VPN Client to connect to some other computers outside of our internal network. Our connection to the

Re: Dell 1950 for PF firewall

2008-02-02 Thread shinny knight
Wojciech Puchar [EMAIL PROTECTED] wrote: Memory: 4GB 667MHz (4x1GB), Dual Ranked DIMMs incredibly important for firewall to have 4GB RAM. why not 64GB or more? ;) ___ freebsd-questions@freebsd.org mailing list

Re: PF firewall

2007-12-07 Thread shinny knight
ajtiM wrote: Hi! I am a new FreeBSD 7.0 beta3 user and I have standalone computer connected to the internet (cable). I use both, console and KDE desktop. I tried to setup PF firewall for the standalone computer but I have a problem with internal messages (mail) which are blocked

Re: PF firewall

2007-12-07 Thread Erik Norgaard
ajtiM wrote: Hi! I am a new FreeBSD 7.0 beta3 user and I have standalone computer connected to the internet (cable). I use both, console and KDE desktop. I tried to setup PF firewall for the standalone computer but I have a problem with internal messages (mail) which are blocked if firewall

Re: PF firewall

2007-12-07 Thread Roland Smith
On Fri, Dec 07, 2007 at 06:20:37AM -0600, ajtiM wrote: Hi! I am a new FreeBSD 7.0 beta3 user and I have standalone computer connected to the internet (cable). I use both, console and KDE desktop. I tried to setup PF firewall for the standalone computer but I have a problem with internal

PF firewall

2007-12-07 Thread ajtiM
Hi! I am a new FreeBSD 7.0 beta3 user and I have standalone computer connected to the internet (cable). I use both, console and KDE desktop. I tried to setup PF firewall for the standalone computer but I have a problem with internal messages (mail) which are blocked if firewall running

DNS and mail servers behind a PF firewall?

2007-02-26 Thread Jacques Beigbeder
Hello, My question is related to PF performances with large state tables. FreeBSD : 5.5 hw.model: Intel(R) Xeon(TM) CPU 3.20GHz hw.physmem: 2138378240 = 2 Gb If I put a mail server 20 SMTP hits per second (thanks to spam...) 15 seconds per SMTP dialog 90 seconds for PF

Re: DNS and mail servers behind a PF firewall?

2007-02-26 Thread J65nko
On 2/26/07, Jacques Beigbeder [EMAIL PROTECTED] wrote: Hello, My question is related to PF performances with large state tables. FreeBSD : 5.5 hw.model: Intel(R) Xeon(TM) CPU 3.20GHz hw.physmem: 2138378240 = 2 Gb If I put a mail server 20 SMTP hits per second (thanks to spam...)

Re: pf firewall for a server

2006-07-26 Thread Peter N. M. Hansteen
Jonathan Horne [EMAIL PROTECTED] writes: ive been googling for a while now this evening, but have unsuccesfully found any examples on how to firewall a server. i do *not* want to build a router, and unfortunatly, every article i seem to find wants to tell me how to build a router! The same

Re: pf firewall for a server

2006-07-26 Thread RW
On Wednesday 26 July 2006 02:30, Jonathan Horne wrote: ive been googling for a while now this evening, but have unsuccesfully found any examples on how to firewall a server. i do *not* want to build a router, and unfortunatly, every article i seem to find wants to tell me how to build a

OpenBSD PF firewall in Freebsd

2006-07-25 Thread Ivan Levchenko
Hello all, Is PF installed with the base system in FreeBSD 6.1? I see that there is IPF, is it the same thing? I didn't find PF in the ports tree, so thats why i'm asking. Thanks! ___ freebsd-questions@freebsd.org mailing list

Re: OpenBSD PF firewall in Freebsd

2006-07-25 Thread Giorgos Keramidas
On 2006-07-25 18:53, Ivan Levchenko [EMAIL PROTECTED] wrote: Hello all, Is PF installed with the base system in FreeBSD 6.1? I see that there is IPF, is it the same thing? I didn't find PF in the ports tree, so thats why i'm asking. Yes, PF is part of the base system in recent FreeBSD

RE: OpenBSD PF firewall in Freebsd

2006-07-25 Thread fbsd
@freebsd.org Subject: OpenBSD PF firewall in Freebsd Hello all, Is PF installed with the base system in FreeBSD 6.1? I see that there is IPF, is it the same thing? I didn't find PF in the ports tree, so thats why i'm asking. Thanks! ___ freebsd-questions

Re: OpenBSD PF firewall in Freebsd

2006-07-25 Thread Ivan Levchenko
PROTECTED] Behalf Of Ivan Levchenko Sent: Tuesday, July 25, 2006 11:53 AM To: freebsd-questions@freebsd.org Subject: OpenBSD PF firewall in Freebsd Hello all, Is PF installed with the base system in FreeBSD 6.1? I see that there is IPF, is it the same thing? I didn't find PF in the ports tree, so

pf firewall for a server

2006-07-25 Thread Jonathan Horne
ive been googling for a while now this evening, but have unsuccesfully found any examples on how to firewall a server. i do *not* want to build a router, and unfortunatly, every article i seem to find wants to tell me how to build a router! i just want to learn how to build a simple pf config

RE: pf firewall for a server

2006-07-25 Thread fbsd
why don't you try reading the firewall section of the handbook. it has working example rule set you can copy -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of Jonathan Horne Sent: Tuesday, July 25, 2006 9:31 PM To: freebsd-questions@freebsd.org Subject: pf

Re: pf firewall for a server

2006-07-25 Thread Darrin Chandler
On Tue, Jul 25, 2006 at 08:30:46PM -0500, Jonathan Horne wrote: ive been googling for a while now this evening, but have unsuccesfully found any examples on how to firewall a server. i do *not* want to build a router, and unfortunatly, every article i seem to find wants to tell me how to

Re: kern.ipc.somaxconn should be high for a PF firewall with a lot of states

2006-05-31 Thread Lowell Gilbert
Iantcho Vassilev [EMAIL PROTECTED] writes: kern.ipc.somaxconn is for handling more incoming connections,right? Well, kind of. It's a systemwide limit on the maximum number of connections that a given socket can accept. but

Re: kern.ipc.somaxconn should be high for a PF firewall with a lot of states

2006-05-31 Thread Iantcho Vassilev
On 5/31/06, Lowell Gilbert [EMAIL PROTECTED] wrote: Iantcho Vassilev [EMAIL PROTECTED] writes: kern.ipc.somaxconn is for handling more incoming connections,right? Well, kind of. It's a systemwide limit on the maximum number of connections that a given socket can accept.

kern.ipc.somaxconn should be high for a PF firewall with a lot of states

2006-05-29 Thread Iantcho Vassilev
kern.ipc.somaxconn is for handling more incoming connections,right? but does firewall connections are considered incoming? ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send

Re: A secure connection to an SCO Unix 5.2 behind a pf firewall.

2005-08-04 Thread Martin Welk
On Wed, Aug 03, 2005 at 05:06:37PM -0500, [EMAIL PROTECTED] wrote: I would appreciate any suggestions for a reasonably secure solution. I just found all this out and am totally blank. Have a look at OpenVPN (http://www.openvpn.org/), it is available as a FreeBSD port and it comes with a

Re: A secure connection to an SCO Unix 5.2 behind a pf firewall.

2005-08-04 Thread eculp
Quoting Martin Welk [EMAIL PROTECTED]: On Wed, Aug 03, 2005 at 05:06:37PM -0500, [EMAIL PROTECTED] wrote: I would appreciate any suggestions for a reasonably secure solution. I just found all this out and am totally blank. Have a look at OpenVPN (http://www.openvpn.org/), it is available

A secure connection to an SCO Unix 5.2 behind a pf firewall.

2005-08-03 Thread eculp
has a simple pf firewall with only a few ports open and opening ports isn't a problem. The application is a terminal session. Thirty users login in to it as root all with windows terminal sessions except for the modem connections and to make it more fun I shouldn't modify the SCO box because

RE: A secure connection to an SCO Unix 5.2 behind a pf firewall.

2005-08-03 Thread eculp
Quoting Gayn Winters [EMAIL PROTECTED]: -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED] Sent: Wednesday, August 03, 2005 3:07 PM To: freebsd-questions@freebsd.org Subject: A secure connection to an SCO Unix 5.2 behind a pf firewall

Re: PF firewall log problems

2005-07-08 Thread Hornet
buffer write cycle time. How do tell PF in rc.conf these over ride options?? -Original Message- From: Hornet [mailto:[EMAIL PROTECTED] Sent: Thursday, July 07, 2005 8:54 PM To: [EMAIL PROTECTED] Cc: [EMAIL PROTECTED] ORG Subject: Re: PF firewall log problems On 7/7/05

Re: Does PF firewall have stateless rules

2005-07-07 Thread Giorgos Keramidas
On 2005-07-06 21:34, fbsd_user [EMAIL PROTECTED] wrote: Does the OpenBSD Packet Filter firewall have stateless rules? Yes. ___ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send

PF firewall log problems

2005-07-07 Thread fbsd_user
How can I change the default wait time for PF buffer writes to the log file? The log records are being held in the buffers for a long time before being written out. I want to change this to a shorter time. Are there any tools or ports for use on the PF log file to create better standardized

Re: PF firewall log problems

2005-07-07 Thread Hornet
On 7/7/05, fbsd_user [EMAIL PROTECTED] wrote: How can I change the default wait time for PF buffer writes to the log file? The log records are being held in the buffers for a long time before being written out. I want to change this to a shorter time. How are you viewing the data? Realtime

RE: PF firewall log problems

2005-07-07 Thread fbsd_user
these over ride options?? -Original Message- From: Hornet [mailto:[EMAIL PROTECTED] Sent: Thursday, July 07, 2005 8:54 PM To: [EMAIL PROTECTED] Cc: [EMAIL PROTECTED] ORG Subject: Re: PF firewall log problems On 7/7/05, fbsd_user [EMAIL PROTECTED] wrote: How can I change the default wait time

Does PF firewall have stateless rules

2005-07-06 Thread fbsd_user
Does the OpenBSD Packet Filter firewall have stateless rules? Meaning, if I coded a rule to pass in for port 23 without any of the different state options coded, do I also have to code the same kind of rule to allow that port 23 packet back out like in IPFW. Or is there no stateless rules in PF?

PF firewall using anchors

2005-07-05 Thread fbsd_user
I am running 5.4 using the run time loadable module for PF firewall. The PF rules load and work fine. The main rule set contains 2 anchor rules. I can add rules to the in core anchor name and then list the anchor and see the rules are really there. Problem is the anchor rules are never being

PF firewall using anchors

2005-07-04 Thread fbsd_user
I am running 5.4 using the run time loadable module for PF firewall. The PF rules load and work fine. The main rule set contains 2 anchor rules. I can add rules to the in core anchor name and then list the anchor and see the rules are really there. Problem is the anchor rules are never being