Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 20 Aug 2005 00:46:37 +0300
From:      Giorgos Keramidas <keramida@ceid.upatras.gr>
To:        Gareth Campbell <gcampbell@orcon.net.nz>
Cc:        freebsd-questions@freebsd.org
Subject:   Re: Internet firewall
Message-ID:  <20050819214637.GA10088@flame.pc>
In-Reply-To: <43064B2F.7050605@orcon.net.nz>
References:  <43064B2F.7050605@orcon.net.nz>

next in thread | previous in thread | raw e-mail | index | archive | help
On 2005-08-20 09:12, Gareth Campbell <gcampbell@orcon.net.nz> wrote:
> Hey guys,
>
> I'm a newbie and have got my box all set up with FreeBSD 5.4, fluxbox
> wm, firefox, thunderbird etc...  It's all looking awesome, with
> transparency, and working well.  I run it on dial-up ppp but haven't set
> up any firewall.  Should I be setting one up?

Yes, definitely.

It takes about 4-5 seconds when I connect with my dialup account from
home and then incoming connections start coming from spyware, trojans
and misc. other scanners :-)

> If so, do I use one of the bundled firewalls or can someone recommend
> one that would suit my purposes?  This is a stand-alone box, not on a
> home network.

The Handbook has a relatively nice chapter on firewalls.

At my home workstation (that uses a dialup connection to the world) and
on my laptop (that spends a lot of time connected in a corporate
network), I use the PF firewall with exactly the same configuration on
both machines:

	- Allow all outgoing connections
	- Allow *some* incoming connections
	- Block everything else

The ``/etc/pf.conf'' file can be found at:

	http://people.freebsd.org/~keramida/files/pf.conf

This and the Handbook chapter about PF will give a good head start :)

- Giorgos




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20050819214637.GA10088>