Re: RES: Migration from IPTABLES to PF

2009-05-06 Thread William Chivers
: William Chivers [mailto:william.chiv...@newcastle.edu.au] Enviada em: segunda-feira, 4 de maio de 2009 22:46 Para: Ricardo Augusto de Souza; misc@openbsd.org Assunto: Re: Migration from IPTABLES to PF This is a great advertisement for OpenBSD, PF, and keeping things simple in general, mind if I

Re: RES: Migration from IPTABLES to PF

2009-05-06 Thread Nenhum_de_Nos
Chivers [mailto:william.chiv...@newcastle.edu.au] Enviada em: segunda-feira, 4 de maio de 2009 22:46 Para: Ricardo Augusto de Souza; misc@openbsd.org Assunto: Re: Migration from IPTABLES to PF This is a great advertisement for OpenBSD, PF, and keeping things simple in general, mind if I use

RES: Migration from IPTABLES to PF

2009-05-05 Thread Ricardo Augusto de Souza
that is it. -Mensagem original- De: William Chivers [mailto:william.chiv...@newcastle.edu.au] Enviada em: segunda-feira, 4 de maio de 2009 22:46 Para: Ricardo Augusto de Souza; misc@openbsd.org Assunto: Re: Migration from IPTABLES to PF This is a great advertisement for OpenBSD, PF, and keeping

Re: RES: Migration from IPTABLES to PF

2009-05-05 Thread William Chivers
: Ricardo Augusto de Souza; misc@openbsd.org Assunto: Re: Migration from IPTABLES to PF This is a great advertisement for OpenBSD, PF, and keeping things simple in general, mind if I use it Ricardo? As for your original question, I wouldn't even try to convert your iptables, especially using some

Re: RES: Migration from IPTABLES to PF

2009-05-05 Thread Tomáš Bodžár
process ( i dont have statistics about volume yet) So that B is it. -Mensagem original- De: William Chivers [mailto:william.chiv...@newcastle.edu.au] Enviada em: segunda-feira, 4 de maio de 2009 22:46 Para: Ricardo Augusto de Souza; misc@openbsd.org Assunto: Re: Migration from

Migration from IPTABLES to PF

2009-05-04 Thread Ricardo Augusto de Souza
Hi, I have a firewall running on a Fedora Core 4 (STentz) with iptables. The Guy Who installed it left our company some months ago. I spent some years far from iptables, now i have to migrate this firewall to PF. THere are some 'special' features on this firewall, i need some documentation or

Re: Migration from IPTABLES to PF

2009-05-04 Thread Jason Dixon
On Mon, May 04, 2009 at 02:17:33PM -0300, Ricardo Augusto de Souza wrote: Hi, I have a firewall running on a Fedora Core 4 (STentz) with iptables. The Guy Who installed it left our company some months ago. I spent some years far from iptables, now i have to migrate this firewall to PF.

Re: Migration from IPTABLES to PF

2009-05-04 Thread John Chronister
Ricardo, Why don't you try Firewall Builder. http://www.fwbuilder.org/ It handles iptables, pf, and others. Should be able to import your iptables ruleset ( created by doing something like /sbin/iptables-save turdwall.txt ) and then convert it to a pf.conf. You will still want to manually

ENC: Migration from IPTABLES to PF

2009-05-04 Thread Ricardo Augusto de Souza
. -Mensagem original- De: Jason Dixon [mailto:ja...@dixongroup.net] Enviada em: segunda-feira, 4 de maio de 2009 14:59 Para: Ricardo Augusto de Souza Cc: misc@openBSD.org Assunto: Re: Migration from IPTABLES to PF On Mon, May 04, 2009 at 02:17:33PM -0300, Ricardo Augusto de Souza wrote: Hi, I

Re: Migration from IPTABLES to PF

2009-05-04 Thread Marco Peereboom
MY EYES!!! make it stop bleeding!!! On Mon, May 04, 2009 at 02:17:33PM -0300, Ricardo Augusto de Souza wrote: Hi, I have a firewall running on a Fedora Core 4 (STentz) with iptables. The Guy Who installed it left our company some months ago. I spent some years far from iptables, now i have

Re: Migration from IPTABLES to PF

2009-05-04 Thread Mark Shroyer
On Mon, May 04, 2009 at 02:17:33PM -0300, Ricardo Augusto de Souza wrote: Hi, I have a firewall running on a Fedora Core 4 (STentz) with iptables. The Guy Who installed it left our company some months ago. I spent some years far from iptables, now i have to migrate this firewall to PF.

Re: Migration from IPTABLES to PF

2009-05-04 Thread Kevin Wilcox
2009/5/4 Ricardo Augusto de Souza ricardo.so...@cmtsp.com.br: #___ # Protecao do KERNEL #___ #Enable forwarding in kernel echo 1

Re: ENC: Migration from IPTABLES to PF

2009-05-04 Thread Mark Shroyer
On Mon, May 04, 2009 at 03:12:20PM -0300, Ricardo Augusto de Souza wrote: Thanks. I already know those documentation. I wish i could find a documentation about this on PF: #___ # Protecao do KERNEL

RES: Migration from IPTABLES to PF

2009-05-04 Thread Ricardo Augusto de Souza
...@openbsd.org] Em nome de Mark Shroyer Enviada em: segunda-feira, 4 de maio de 2009 15:34 Para: misc@openBSD.org Assunto: Re: Migration from IPTABLES to PF On Mon, May 04, 2009 at 02:17:33PM -0300, Ricardo Augusto de Souza wrote: Hi, I have a firewall running on a Fedora Core 4 (STentz

Re: Migration from IPTABLES to PF

2009-05-04 Thread Gonzalo Lionel Rodriguez
jajajaja i think the same. grrr 2009/5/4 Marco Peereboom sl...@peereboom.us: MY EYES!!! make it stop bleeding!!! On Mon, May 04, 2009 at 02:17:33PM -0300, Ricardo Augusto de Souza wrote: Hi, I have a firewall running on a Fedora Core 4 (STentz) with iptables. The Guy Who installed it left

Re: Migration from IPTABLES to PF

2009-05-04 Thread Jason Dixon
On Mon, May 04, 2009 at 04:34:55PM -0300, Gonzalo Lionel Rodriguez wrote: 2009/5/4 Marco Peereboom sl...@peereboom.us: MY EYES!!! make it stop bleeding!!! jajajaja i think the same. grrr LOL, you ain't seen nothing yet. Look at the extended version he just sent out. :) -- Jason Dixon

Re: Migration from IPTABLES to PF

2009-05-04 Thread Gonzalo Lionel Rodriguez
jaja OMG... i love PF and OpenBSD. 2009/5/4 Jason Dixon ja...@dixongroup.net: On Mon, May 04, 2009 at 04:34:55PM -0300, Gonzalo Lionel Rodriguez wrote: 2009/5/4 Marco Peereboom sl...@peereboom.us: MY EYES!!! make it stop bleeding!!! jajajaja i think the same. grrr LOL, you ain't seen

Re: Migration from IPTABLES to PF

2009-05-04 Thread Mark Shroyer
On Mon, May 04, 2009 at 04:46:16PM -0300, Gonzalo Lionel Rodriguez wrote: jaja OMG... i love PF and OpenBSD. 2009/5/4 Jason Dixon ja...@dixongroup.net: LOL, you ain't seen nothing yet. Look at the extended version he just sent out. :) To be fair, I've seen some pretty horrid pf.conf

Re: RES: Migration from IPTABLES to PF

2009-05-04 Thread Mark Shroyer
: segunda-feira, 4 de maio de 2009 15:34 Para: misc@openBSD.org Assunto: Re: Migration from IPTABLES to PF [...] Is that actually all there is to the firewall setup? This script creates a bunch of chains for performing various actions on packets, but it doesn't actually add any rules

Re: Migration from IPTABLES to PF

2009-05-04 Thread Gonzalo Lionel Rodriguez
Dont be fair ;) 2009/5/4 Mark Shroyer subscriber+open...@markshroyer.com: On Mon, May 04, 2009 at 04:46:16PM -0300, Gonzalo Lionel Rodriguez wrote: jaja OMG... i love PF and OpenBSD. 2009/5/4 Jason Dixon ja...@dixongroup.net: LOL, you ain't seen nothing yet. Look at the extended version

Re: Migration from IPTABLES to PF

2009-05-04 Thread Jason Dixon
On Mon, May 04, 2009 at 04:14:45PM -0400, Mark Shroyer wrote: On Mon, May 04, 2009 at 04:46:16PM -0300, Gonzalo Lionel Rodriguez wrote: jaja OMG... i love PF and OpenBSD. 2009/5/4 Jason Dixon ja...@dixongroup.net: LOL, you ain't seen nothing yet. Look at the extended version he just

Re: Migration from IPTABLES to PF

2009-05-04 Thread Giancarlo Razzolini
Mark Shroyer escreveu: On Mon, May 04, 2009 at 04:46:16PM -0300, Gonzalo Lionel Rodriguez wrote: jaja OMG... i love PF and OpenBSD. 2009/5/4 Jason Dixon ja...@dixongroup.net: LOL, you ain't seen nothing yet. Look at the extended version he just sent out. :) To be fair, I've

Re: Migration from IPTABLES to PF

2009-05-04 Thread William Chivers
This is a great advertisement for OpenBSD, PF, and keeping things simple in general, mind if I use it Ricardo? As for your original question, I wouldn't even try to convert your iptables, especially using some magic tool to do it. Decide what you want your firewall to do and start from scratch