Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 18 Nov 2000 17:45:08 -0500
From:      Sam Carleton <scarleton@bigfoot.com>
To:        FreeBSD Questions <freebsd-questions@FreeBSD.ORG>
Subject:   need help setting up firewall
Message-ID:  <3A170674.1DFCF40@bigfoot.com>

next in thread | raw e-mail | index | archive | help
I have read through the “Setting-up a Dual-Homed Host using IPFW and
NATD”, but the script is not working for me.  My setup is a bit
different.  My connectivity is via a cable modem.

* In the article, it looks like the author was setup with a static
external IP address.  I have a dynamic ip address.  How do I allow the
DHCP server (Cable Modem) broadcasts to get to my outside NIC?

* In the article, the author is only allowing the inside connections to
connect to known DNS servers.  I run a caching DNS server on the inside
so I need to have the firewall configured so that the internal DNS
server can talk to any other DNS server.

* In the article, it looks like the author is allowing things like HTTP
and SSH to come into the firewall machine.  I want those things to be
passed onto another internal machine.

Attached you will find my modifications to the rc.firewall script and
relavent snips of rc.conf.  If you have any thoughts on what I am doing
wrong, please drop me an email.  Thanks!

------------rc.conf------------
firewall_enable="Yes"
firewall_type="Simple"
firewall_script="/etc/rc.firewall"
firewall_quite="No"
natd_program="/sbin/natd"
natd_enable="Yes"
natd_interface="ep0"
natd_flags="-f /etc/natd.conf"

------------rc.firewall------------
############
# Setup system for firewall service.
# $FreeBSD: src/etc/rc.firewall,v 1.30.2.4 2000/05/28 19:17:15 asmodai
Exp $

# Suck in the configuration variables.
if [ -r /etc/defaults/rc.conf ]; then
 . /etc/defaults/rc.conf
 source_rc_confs
elif [ -r /etc/rc.conf ]; then
 . /etc/rc.conf
fi

############
# Define the firewall type in /etc/rc.conf.  Valid values are:
#   open     - will allow anyone in
#   client   - will try to protect just this machine
#   simple   - will try to protect a whole network
#   closed   - totally disables IP services except via lo0 interface
#   UNKNOWN  - disables the loading of firewall rules.
#   filename - will load the rules in the given filename (full path
required)
#
# For ``client'' and ``simple'' the entries below should be customized
# appropriately.

############
#
# If you don't know enough about packet filtering, we suggest that you
# take time to read this book:
#
# Building Internet Firewalls
# Brent Chapman and Elizabeth Zwicky
#
# O'Reilly & Associates, Inc
# ISBN 1-56592-124-0
# http://www.ora.com/
#
# For a more advanced treatment of Internet Security read:
#
# Firewalls & Internet Security
# Repelling the wily hacker
# William R. Cheswick, Steven M. Bellowin
#
# Addison-Wesley
# ISBN 0-201-6337-4
# http://www.awl.com/
#

if [ -n "${1}" ]; then
 firewall_type="${1}"
fi

############
# Set quiet mode if requested
#
case ${firewall_quiet} in
[Yy][Ee][Ss])
 fwcmd="/sbin/ipfw -q"
 ;;
*)
 fwcmd="/sbin/ipfw"
 ;;
esac

############
# Flush out the list before we begin.
#
${fwcmd} -f flush

############
# These rules are required for using natd.  All packets are passed to
# natd before they encounter your remaining rules.  The firewall rules
# will then be run again on each packet after translation by natd,
# minus any divert rules (see natd(8)).
#
case ${natd_enable} in
[Yy][Ee][Ss])
 if [ -n "${natd_interface}" ]; then
       ${fwcmd} add 50 divert natd all from any to any via
${natd_interface}
 fi
 ;;
esac

############
# If you just configured ipfw in the kernel as a tool to solve network
# problems or you just want to disallow some particular kinds of traffic

# then you will want to change the default policy to open.  You can also

# do this as your only action by setting the firewall_type to ``open''.
#
# ${fwcmd} add 65000 pass all from any to any

############
# Only in rare cases do you want to change these rules
#
${fwcmd} add 100 pass all from any to any via lo0
${fwcmd} add 200 deny all from any to 127.0.0.0/8
# If you're using 'options BRIDGE', uncomment the following line to pass

ARP
#${fwcmd} add 300 pass udp from 0.0.0.0 2054 to 0.0.0.0


# Prototype setups.
#
case ${firewall_type} in
[Oo][Pp][Ee][Nn])
 ${fwcmd} add 65000 pass all from any to any
 ;;

[Cc][Ll][Ii][Ee][Nn][Tt])
 ############
 # This is a prototype setup that will protect your system somewhat
 # against people from outside your own network.
 ############

 # set these to your network and netmask and ip
 net="192.0.2.0"
 mask="255.255.255.0"
 ip="192.0.2.1"

 # Allow any traffic to or from my own net.
 ${fwcmd} add pass all from ${ip} to ${net}:${mask}
 ${fwcmd} add pass all from ${net}:${mask} to ${ip}

 # Allow TCP through if setup succeeded
 ${fwcmd} add pass tcp from any to any established

 # Allow IP fragments to pass through
 ${fwcmd} add pass all from any to any frag

 # Allow setup of incoming email
 ${fwcmd} add pass tcp from any to ${ip} 25 setup

 # Allow setup of outgoing TCP connections only
 ${fwcmd} add pass tcp from ${ip} to any setup

 # Disallow setup of all other TCP connections
 ${fwcmd} add deny tcp from any to any setup

 # Allow DNS queries out in the world
 ${fwcmd} add pass udp from any 53 to ${ip}
 ${fwcmd} add pass udp from ${ip} to any 53

 # Allow NTP queries out in the world
 ${fwcmd} add pass udp from any 123 to ${ip}
 ${fwcmd} add pass udp from ${ip} to any 123

 # Everything else is denied by default, unless the
 # IPFIREWALL_DEFAULT_TO_ACCEPT option is set in your kernel
 # config file.
 ;;

[Ss][Ii][Mm][Pp][Ll][Ee])
 ############
 # This is a prototype setup for a simple firewall.  Configure this
 # machine as a named server and ntp server, and point all the machines
 # on the inside at this machine for those services.
 ############

 # set these to your outside interface network and netmask and ip
 oif="ep0"
# onet="192.0.2.0"
# omask="255.255.255.240"
# oip="192.0.2.1"

 # set these to your inside interface network and netmask and ip
 iif="xl1"
 inet="192.168.0.0"
 imask="255.255.255.0"
 iip="192.168.0.6"

 # Stop spoofing
 ${fwcmd} add deny all from ${inet}:${imask} to any in via ${oif}
# ${fwcmd} add deny all from ${onet}:${omask} to any in via ${iif}

 # Stop RFC1918 nets on the outside interface
 ${fwcmd} add deny all from 10.0.0.0/8 to any via ${oif}
 ${fwcmd} add deny all from any to 10.0.0.0/8 out via ${oif}
 ${fwcmd} add deny all from 172.16.0.0/12 to any via ${oif}
 ${fwcmd} add deny all from any to 172.16.0.0/12 out via ${oif}
 ${fwcmd} add deny all from 192.168.0.0/16 to any via ${oif}
 ${fwcmd} add deny all from any to 192.168.0.0/16 out via ${oif}

 # Stop draft-manning-dsua-01.txt nets on the outside interface
 ${fwcmd} add deny all from 0.0.0.0/8 to any via ${oif}
 ${fwcmd} add deny all from any to 0.0.0.0/8 via ${oif}
 ${fwcmd} add deny all from 169.254.0.0/16 to any via ${oif}
 ${fwcmd} add deny all from any to 169.254.0.0/16 via ${oif}
 ${fwcmd} add deny all from 192.0.2.0/24 to any via ${oif}
 ${fwcmd} add deny all from any to 192.0.2.0/24 via ${oif}
 ${fwcmd} add deny all from 224.0.0.0/4 to any via ${oif}
 ${fwcmd} add deny all from any to 224.0.0.0/4 via ${oif}
 ${fwcmd} add deny all from 240.0.0.0/4 to any via ${oif}
 ${fwcmd} add deny all from any to 240.0.0.0/4 via ${oif}

 # Allow TCP through if setup succeeded
 ${fwcmd} add pass tcp from any to any established

 # Allow IP fragments to pass through
 ${fwcmd} add pass all from any to any frag

 # HTTP - Allow access to our web server
 ${fwcmd} add pass tcp from any to any 80 setup

 # SMTP - Allow access to sendmail for incoming e-mail
 ${fwcmd} add pass tcp from any to any 25 setup

 # FTP - Allow incoming data channel for outgoing connections,
 # Reject&Log all incoming control connections
 ${fwcmd} add pass tcp from any 20 to any 1024-65535 setup
 ${fwcmd} add deny tcp log tcp from any to any 21 in via ${oif} setup

 # SSH Login - Allow & Log all incoming
 ${fwcmd} add pass log tcp from any to any 22 in via ${oif} setup

 # IDENT - Reset incoming connections
 ${fwcmd} add reset tcp from any to any 113 in via ${oif} setup

 # Reject&Log all setup of incoming connections from the outside
 ${fwcmd} add deny log tcp from any to any in via ${oif} setup

 # Allow setup of any other TCP connection
 ${fwcmd} add pass tcp from any to any setup

 # Allow access to our DNS
# ${fwcmd} add pass tcp from any to ${oif} 53 setup
# ${fwcmd} add pass udp from any to ${oif} 53
# ${fwcmd} add pass udp from ${oif} 53 to any

 # Allow DNS queries out in the world
 ${fwcmd} add pass udp from any 53 to ${oif}
 ${fwcmd} add pass udp from ${oif} to any 53

 # Allow NTP queries out in the world
 ${fwcmd} add pass udp from any 123 to any 123 via ${oif}
 ${fwcmd} add pass udp from any 123 to any via ${iif}
 ${fwcmd} add pass udp from any to any 123 via ${iif}

 # TRACEROUTE - Allow outgoing, but not incoming
 ${fwcmd} add pass udp from any to any 33434-33523 out via ${oif}


 ### ICMP RULES

 # ICMP packets
 # Allow all ICMP packets on internal interface
 ${fwcmd} add pass icmp from any to any via ${iif}

 # Allow outgoing pings, but not incoming
 ${fwcmd} add pass icmp from any to any icmptypes 8 out via ${oif}
 ${fwcmd} add pass icmp from any to any icmptypes 0 in via ${oif}

 # Allow Destination Unreachable, Source Quench, Time Exceeded, and Bad
Head
 ${fwcmd} add pass icmp from any to any icmptypes 3,4,11,12 via ${oif}

 # Deny the rest of them
 ${fwcmd} add deny icmp from any to any


 # Everything else is denied by default, unless the
 # IPFIREWALL_DEFAULT_TO_ACCEPT option is set in your kernel
 # config file.
 ;;

[Uu][Nn][Kk][Nn][Oo][Ww][Nn])
 ;;
*)
 if [ -r "${firewall_type}" ]; then
  ${fwcmd} ${firewall_flags} ${firewall_type}
 fi
 ;;
esac



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3A170674.1DFCF40>