Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 17 Jul 2006 13:18:26 -0500
From:      "Travis H." <solinym@gmail.com>
To:        "Simon L. Nielsen" <simon@nitro.dk>
Cc:        freebsd-security@freebsd.org, freebsd-pf@freebsd.org
Subject:   Re: Any ongoing effort to port /etc/rc.d/pf_boot, /etc/pf.boot.conf from NetBSD ?
Message-ID:  <d4f1333a0607171118r5225d448wba53ef44ff38ada5@mail.gmail.com>
In-Reply-To: <20060717122127.GC1087@zaphod.nitro.dk>
References:  <44B7715E.8050906@suutari.iki.fi> <20060714154729.GA8616@psconsult.nl> <44B7D8B8.3090403@suutari.iki.fi> <20060716182315.GC3240@insomnia.benzedrine.cx> <20060717122127.GC1087@zaphod.nitro.dk>

next in thread | previous in thread | raw e-mail | index | archive | help
On 7/17/06, Simon L. Nielsen <simon@nitro.dk> wrote:
> Personally I would still like a default to deny knob, but that's
> mainly to handle the case of an invalid ruleset which causes pf to be
> left open.  Yes, this is only a problem when the admin screws up, but
> it happens...

Since you mention it, this would have been useful to me too.  My
dynamic firewall daemon manages the ruleset (see homepage), and not
all rules are sent to pf at once, and the active rules persist across
reboots.  In my case, I made a simple error in the script, it flushed
the rules (I think...), failed to load a ruleset, but in any case I
ended up with an invalid ruleset at boot time, and consequently a
completely open firewall.

Subsequent to this, I made sure it wouldn't happen again in various
ways, but since I didn't have adequate reporting I didn't know it was
wide open until several days later.  It may be that I hung myself, but
I'm pretty good with firewalls and if it can happen to me it can
happen to others.   OTOH, if it had had default block, I would have
known immediately.

Fortunately I didn't seem to suffer any ill effects; the obsd firewall
runs minimal services.
-- 
``I am not a pessimist.  To perceive evil where it exists is, in my
opinion, a form of optimism.'' -- Roberto Rossellini
http://www.lightconsulting.com/~travis/ -><-
GPG fingerprint: 9D3F 395A DAC5 5CCC 9066  151D 0A6B 4098 0C55 1484



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?d4f1333a0607171118r5225d448wba53ef44ff38ada5>