firewall

  1. S

    Other Forums firewalled out?

    Posting this from a phone on mobile network. I tried accessing forums.freebsd.org from my computer connected by wire, from different browsers and by another device connected to wifi from the same network. Forums.freebsd.org is still not reachable.
  2. scott_sch

    PF Fundamentals of packet filtering with pf

    The purpose of this post is to try and clarify a few basic ideas in packet filtering that I'm having trouble reducing to firm principles in practice. 0. PF lives in the kernel and handles all packets as they pass between NI(C)'s and daemons 1. Packets are identified by the NIC of origin and...
  3. N

    PF PF firewall pf.conf Review

    Hi all, Could somebody with some knowledge and experience have a look at my pf.conf before I start using it, to make sure I'm not doing anything stupid with it? I am using FreeBSD 12.2 on a laptop connected via wifi to my ISP router and the VPN provided for work. I am using OpenVPN and...
  4. I

    Solved Hardware for router

    Hi! I was not sure if I should put this to networking or off topic. I am looking for a relative cheap ITX motherboard and computer case which can handle 2x8 PCI-E cards with bifurcation without cutting metal or other kind of tinkering. I'd like to have something small for my home network, but I...
  5. J

    Solved Firewall vs Softether VPN

    Hello everyone, I'm having little problem with my setup of FreeBSD and Softether VPN. I want to be able to make connection with my VPN Server while firewall_type="closed". I thought I had to add these rules: add allow udp from any to any 67 setup keep-state add allow udp from any to any 68...
  6. l008com

    PF Best `pf` Rule Format?

    As my rules get more complicated, i've gone from "from any", to "from ip-address", to "from en0". What I noticed is that when I specify via en0/en1, `pf` makes a rule for every IP address on that interface. Even though other IPs in my setup are covered by other rules. Including IPv6 addresses...
  7. FzZzT

    pr and bridges and squids, oh my!

    Hello, I've read a number of other threads and resources (here and elsewhere) but I can't seem to get the correct combination of things to make my scenario work. Some info seems to be outdated or I'm not sure how to fit it in. Maybe it just isn't possible. Hopefully this isn't completely...
  8. E

    I saw on reddit that someone made a BSD server to have websites unblocked at their school, How can I do this?

    According to the reddit post, the kid made a server, and used ssh to connect to it. He had a version of firefox that ran on the chromebooks/PCs on a flashdrive that routed the requests to the BSD server rather than the schools dns filter. I have putty connected, the firefox and flashdrive is...
  9. Nyakov

    Solved Samba server spamming logs

    Hi. I have very simple setup. One windows PC and one FreeBSD server with samba share. I don't need anything regarding windows network management, printing, netbios etc. Only one share. There is my smb4.conf: [global] server string = My Samba Server netbios name = my-samba workgroup = MYHOME...
  10. fedqx

    IPFW [Solved] Blocking Connections

    (Sorry for being a noob, It's my first time on the forums) Hi, I am using a custom firewall rules script, It supposed to block all connections other than the ones specified here but well, it doesn't here is my script: IPF="ipfw -q add" ipfw -q -f flush #loopback $IPF 10 allow all from any to...
  11. J

    Solved Blocking request based on IP address in X-Forwarded-For header

    I have (courtesy of fail2ban + nginx) tables of IPs I would like to stop from accessing the server in any way (ssh, web, etc.). When they try to ssh, pf blocks them like it should. When they access the webserver directly, they get blocked. But when they access via a proxy, I have no idea what...
  12. I

    access sites and some other networking issues

    I have problem to access some sites but not all, but I have internet connectivity normally. Example this site below cannot be accessed: https://www.linode.com/community/questions/2982/im-unable-to-run-telnet-on-localhost-25-how-do-i-fix-it-solved I get the following message in Mozilla; Hmm...
  13. F

    PF Packet tagging with route-to in pf.conf

    nat log (to pflog0) on if0 from 192.168.0.1 tag TAG_PASS tagged TAG_EX -> (if0) label "test" nat log (to pflog0) on if0 from 192.168.0.1 tag TAG_PASS tagged TAG_EX -> (if0) label "test" nat log (to pflog0) on if0 from 192.168.0.1 tag TAG_PASS tagged TAG_EX -> (if0) label "test" no nat from...
  14. M

    Recommended approach to host / domain blocking?

    I'm currently using hblock with Arch Linux on my laptop: and now I'm wondering what the recommended approach for something like this could be when using FreeBSD. What comes to mind: Simply stick to using a hosts file Use a DNS resolver like unbound with a blocklist Use a DNS proxy like...
  15. W

    IPFW Curl getting blocked by IPFW

    Hey people, After spend some days searching about my issue,I come here to try the luck. I 'm runing an webserver using: FreeBSD 12.0 Apache24 2.4.41 curl 7.67.0 Using IPFW as firewall. Main problem is about Curl, this one with IPFW enabled is getting timeout and does not work. Similar...
  16. Killua

    PF GeoIP whitelist or blacklist of states

    Hi Guys, i don't find nothing on the net about GeoIP for PF, I searched a lot but nothing, I need to block states or create a white list of states that can access the server so I can make things easier for myself, could anyone help me? place here at the bottom of my pf configuration that is...
  17. D

    pppoe, jails, firewalls and me

    Hey Community, I want to try something but need some advice before I start. If I open a pppoe connection on a machine which has some jails instantiated, could these (maybe compromised) jails do something nasty with that tun device? In my understanding the kernel creates the pppoe device which...
  18. S

    PF PF Portfowarding HTTP Sometimes can be opened sometime can't be opened

    Hello everyone. to the point, I would to ask something about port portforwarding. is portforwarding very slow connection? My friends opened my server actually is really fast (about 20ms). But when I opened it, it is very slow to opened the web from the my ip public. sometime when I opened it is...
  19. damjank

    FreeBSD 12.0-RELEASE Update successful but kernel modules can not be loaded anymore

    Hello Guys. I installed fresh installation of FreeBSD 12.0 minimal; I then installed minimal packages, the rest was done via ports. I did freebsd-update fetch in install - it wen along OK. Afterwords I get errors like: kldload: can't load pf: Operation not permitted and kldload: can't load...
  20. F

    IPFW ipfw filter for tcp IPv6 on Freebsd 11

    Hi I am using ipfw for firewalling on a FreeBSD 11 box. Unfortunately I cannot wrap my head around the fact that/why the following rule does not match when I initiate a TCP connection to 2a00:1450:4001:814::2003 (that is Google...): ipfw add 340 set 5 count dst-ip6 2a00:1450:4001:814::2003...
Top