A Beginner's Guide to Firewalling with pf
srobb.net
srobb.net
https://home.nuug.no/~peter/pf/en/
he also has a book that I've heard is great, but don't own (yet)
The Book of PF, 3rd Edition
By: Peter N.M. Hansteen
Publisher: No Starch Press
Pub. Date: October 8, 2014
Print ISBN-13: 978-1-59327-589-1
Pages in Print Edition: 248
http://my.safaribooksonline.com/book/operating-systems-and-s...I think it is odd that of lately, that it seems to becoming popular -- as if it is something new. Either way I m happy, something old that is new again and I can spend my time learning something else, maybe k8s? nah, I will pass, some things are just fads.
https://github.com/sinner-/ansible-freebsdvps/blob/master/ro...
The guide touches on how "quick" can speed up rule evaluation. But I think this misses the big picture. I write all the rules I can using "quick", and only omit it when the language constructs provided force me to. E.g. sometimes you need to "match" and so "quick" doesn't apply.
I'd sure like someone to explain to me why "quick" isn't the preferred way or even the only way to do things. As best as I can figure, this awkwardness was inherited from the rules for ipf. But ipf was thrown out of OpenBSD about 15 years ago. I guess it made it easier to convert ipf rules to pf rules if "non-quick" remained the default behavior?
I do the following on my machines:
# cp /etc/pf.conf /etc/pf.conf.good
# crontab -e
*/5 * * * * /sbin/pfctl -f /etc/pf.conf.good
:x
# #now vi /etc/pf.conf; pfctl -f /etc/pf.conf; and if OK: cp /etc/pf.conf /etc/pf.conf.goodIt also seems overcomplex to use sudo from an unprivileged user's crontab rather than just straight execution of the target command from the superuser's crontab. I infer that your # prompt is implying this, too. (-:
All physical hardware has them. All hosting companies offer them via various tricks. This is why.
Just don't recommend stupid things: make them right once and the stupid thing won't ever have to go through your mind.
Using a more apples to apples comparison, pf is way simpler than iptables.
By bringing up UFW which is an iptables wrapper, you're not looking for a pf alternative so much as a pf wrapper. But it was the complexity of iptables that drove development of wrappers like UFW in the first place - pf doesn't really have the same level of need that iptables did.
Personally having used iptables and ipfilter I always thought pf was pretty simple.
I fully understand that Pf is equivalent to iptables, and is a lower level abstraction than UFW. But the question stands; Is there a simple foolproof utility for blocking ports on BSD with a single command? I just don't feel like whitelisting port 80 should require authoring a config file.
Yes. It is called pf.
block in on fxp0 proto tcp to any port { 25 80 }
... blocks incoming email and http connections on the fxp0 interface. That is all you need to put in pf.conf to do that. block in on egress proto tcp to port { 25, 80 } block all
pass proto tcp to port wwwMy current firewall [0] has two physical interfaces, 3 additional "virtual" (VLAN-tagged) interfaces, three RFC-1918 subnets, four IPv6 subnets (dual-stack of course, except for an IPv6-only subnet) with varying degrees of security between the subnets -- and I could not imagine maintaining it with anything but pf.
[0] https://github.com/cunnie/vain.nono.io-etc/blob/master/pf.co...
Are you really saying this[0] is more complex than this?[1][2]
If _anything_ I'm annoyed that linux doesn't have this.
[0]: https://git.drk.sc/darkscience/ds-salt/blob/master/security/...
[1]: https://git.drk.sc/darkscience/ds-salt/blob/master/security/...
[2]: https://git.drk.sc/darkscience/ds-salt/blob/master/security/...
It was a long time ago, though, and my memory may trick me. And if that tool really did exist, it might be unmaintained and outdated.
[0] I though it was called Firestarter, but that tool appears to be Linux/iptables-specific.