From owner-freebsd-questions@FreeBSD.ORG Sun Jul 11 12:44:31 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id D861C16A4CE for ; Sun, 11 Jul 2004 12:44:31 +0000 (GMT) Received: from smtp-09.primus.ca (mail.tor.primus.ca [216.254.136.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id 5F10B43D31 for ; Sun, 11 Jul 2004 12:44:31 +0000 (GMT) (envelope-from gaspar.kiraly@iprimus.com) Received: from 03-127.147.popsite.net ([64.24.178.127] helo=win98) by smtp-09.primus.ca with asmtp (Exim 3.36 #1) id 1Bjdlx-0007qf-0A for freebsd-questions@freebsd.org; Sun, 11 Jul 2004 12:49:38 +0000 Message-ID: <000a01c46745$cbd736e0$0201a8c0@my.domain> From: "Gaspar Kiraly" To: Date: Sun, 11 Jul 2004 08:51:31 -0400 MIME-Version: 1.0 X-Priority: 3 X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook Express 5.50.4807.1700 X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4807.1700 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable X-Content-Filtered-By: Mailman/MimeDel 2.1.1 Subject: Firewall rules for local lan X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 11 Jul 2004 12:44:32 -0000 Hello, I have a quick question for you: I am in the process of setting up ipfw for my server and a small LAN of = two pcs. The FreeBSD server is used as an internet gateway with a dial up = connection (ppp -auto -alias demand). My network connection is working fine, however I am getting more and = more junk mail lately. It looks like some sites are sniffing out my e-mail address, my pc = configs, etc. Hence, I'd like to setup a firewall. I found many good examples, however they deal with a one pc (FreeBSD) = one network card setup. For ex: do I need to add "divert" and "bridge" to the Kernel config = file? How do I set up different rules for for each nic? I'd like to be able to access the FreeBSD server from my local LAN w/o = any restrictions but I do not want the internet sites to do the same = with my server and LAN. Would you have an example setup for this = scenario? The FreeBSD server is also setup to provide address resolution = for the internet. I'd appreciate any help. Gaspar