[FBSD 4.3] Firewall of ipfilter?

Pagina: 1
Acties:

  • Leon
  • Registratie: Maart 2000
  • Laatst online: 19-08 12:12

Leon

Rise Of The Robots

Topicstarter
Ik heb nou dus gewoon FreeBSD geinstalleerd zodat ik er op kan werken als workstation.
Maar nou wil ik natuurlijk niet dat iedereen me lekker kan hacken terwijl ik erachter aan het werken ben (en natuurlijk ook als ik er niet aan werk.. :P) Er zijn genoeg tutorials te vinden over hoe je een gateway maakt en zo met ipfirewall en ipfilter (wat is het verschil trouwens :?) en natd maar hoe moet dat nou als je maar 1 NIC hebt :? moet je dan ook ipnat gebruiken om alles door ipfilter of ipfirewall te routen of niet :?

dus 2 vraagjes eigenlijk.. :P :
  1. wat is het verschil tussen ipfirewall en ipfilter :?
  2. hoe moet ik nou 1 van de 2 configureren zonder nat :? (of juist met? :))
Als het al eerder is geweest dan graag niet roepen van: UTFS of RTFF maar a.u.b. een linkje naar het artikel/tutorial of de thread waar dit is uitgelegd.. :)

Eeuwige n00b


  • Leon
  • Registratie: Maart 2000
  • Laatst online: 19-08 12:12

Leon

Rise Of The Robots

Topicstarter
Niemand :?
Ik heb geduldig gewacht hoor... O-)

Eeuwige n00b


Verwijderd

Je kan het beide tergerlijker tijd gebruiken als redunant firewall.

Persoonlijk kies ik voor ipfilter echt super makkelijk te configureren en de howto is goed inclusief de mailing list ed.

kijk ff hier

  • Infern0
  • Registratie: September 2000
  • Laatst online: 16-03 23:51

Infern0

Hou die ontzettende rust!!

Op zondag 16 september 2001 18:36 schreef fazer het volgende:
dus 2 vraagjes eigenlijk.. :P :
  1. wat is het verschil tussen ipfirewall en ipfilter :?
  2. hoe moet ik nou 1 van de 2 configureren zonder nat :? (of juist met? :))
antw vraag 1.
Super veel verschil is er niet, ipfilter wordt geloof ik iets veiliger gezien (bewijzen heb ik niet). Ik draai zelf ipfilter omdat ik de syntax iets eenvoudiger vind.

antw vraag 2.
je hebt dus geen nat nodig. Hoe configureren is aan je zelf. Je begint meestal met eerste alle poorten dicht te gooien en daarna de poorten open te zetten die je nodig hebt.

goeie links:
[url="hhtp://www.defcon1.org"]hhtp://www.defcon1.org[/url]
http://www.mostgraveconcern.com/freebsd/

hier komt een ned site voor freebsd info >:)
http://www.basdfreaks.nl

http://www.bsdfreaks.nl Home site: http://rob.lensen.nu /me was RobL


  • Leon
  • Registratie: Maart 2000
  • Laatst online: 19-08 12:12

Leon

Rise Of The Robots

Topicstarter
default dichtgooien door dus in je kernel de optie IPFILTER_DEFAULT_BLOCK mee te geven.. :P

Eeuwige n00b


  • Leon
  • Registratie: Maart 2000
  • Laatst online: 19-08 12:12

Leon

Rise Of The Robots

Topicstarter
En wat ik dus bedoelde met het configgen was:
zoekt ie automatisch de regels in /etc/ipf.rules :?
en die linkjes naar die tutorials (kende die van mostgraven al :)) laten regelsets zien voor een nat router en ik zou niet weten hoe dat zonder doorsturen (NAT) zou moeten :?

Eeuwige n00b


  • Infern0
  • Registratie: September 2000
  • Laatst online: 16-03 23:51

Infern0

Hou die ontzettende rust!!

je moet gewoon helemaal niks doen met nat.
je hebt een aparte file met nat rules en die laat je dan gewoon leeg. Je /etc/ipf.rules (bijv) daar zet je de poorten open die JIJ open wilt
code:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
#################################################################
# Outside Interface
#################################################################

#----------------------------------------------------------------
# Allow out all TCP, UDP, and ICMP traffic & keep state on it
# so that it's allowed back in.
#----------------------------------------------------------------
pass out quick on de0 proto tcp from any to any keep state
pass out quick on de0 proto udp from any to any keep state
pass out quick on de0 proto icmp from any to any keep state
block out quick on de0 all

#----------------------------------------------------------------
# Allow bootp traffic in from your ISP's DHCP server only.
# Replace X.X.X.X/32 with your ISP's DHCP server address.
#----------------------------------------------------------------
pass in quick on de0 proto udp from 212.120.66.200/32 to any port = 68 keep state

# loopback pakets left unmolested
pass in quick on lo0 all
pass out quick on lo0 all

# This host only runs sshd, no other services
pass in quick on de0 proto tcp from any to any port = 22 flags S keep state

# Apache Webserver
pass in quick proto tcp from any to any port = 80
pass in quick proto tcp from any to any port = 443

# SMTP
pass in quick proto tcp from any to any port = 25 flags S keep state

# To receive traceroute replies
pass in quick on de0 proto icmp from any to any icmp-type timex keep state
pass in quick on de0 proto icmp from any to xxx.xxx.xxx.xxx/24 icmp-type 0
pass in quick on de0 proto icmp from any to xxx.xxx.xxx.xxx/24 icmp-type 11



#----------------------------------------------------------------

# Outbound traffic from our own IPs is allowed
# Could be made more strict for icmp
pass out quick on de0 proto tcp/udp from xxx.xxx.xxx.xxx/32 to any keep state
pass out quick on de0 proto tcp/udp from 192.168.1.0/24 to any keep state
pass out quick on de0 proto icmp from xxx.xxx.xxx.xxx/32 to any keep state
pass out quick on de0 proto icmp from 192.168.1.0/24 to any keep state

# Block and log all remaining traffic coming into the firewall

# - Block TCP with a RST (to make it appear as if the service
# isn't listening)
# - Block UDP with an ICMP Port Unreachable (to make it appear
# as if the service isn't listening)
# - Block all remaining traffic the good 'ol fashioned way
#----------------------------------------------------------------
block return-rst in log quick on de0 proto tcp from any to any
block return-icmp-as-dest(port-unr) in log quick on de0 proto udp from any to any
block in log quick on de0 all

that's all

http://www.bsdfreaks.nl Home site: http://rob.lensen.nu /me was RobL


  • Leon
  • Registratie: Maart 2000
  • Laatst online: 19-08 12:12

Leon

Rise Of The Robots

Topicstarter
Oke... TnX.. :)
Weer wat geleerd in de wazige *NIX wereld.. :P

Eeuwige n00b

Pagina: 1