Are 4 IPFW rules enough?

Kevin D. Kinsey, DaleCo, S.P. kdk at daleco.biz
Sat Jul 24 12:09:50 PDT 2004


Kevin Curran wrote:

>I have a cable modem and I'm using 4.9 as a NAT router for my home
>network.  I have 4 rules in my ipfw config.  The first enables NAT and
>the last is 65000 allow any to any.
>
>In between I ha 2 rules to deny access to ports 53 and 110 on the
>Internet side.  That's all.  
>
>Here's my thinking: I use inetd.conf to enable only the services I want,
>therefore the ports on which those services are listening I would want
>open.  The two other ports I want to filter on the WAN side are filtered
>by the rules above.  All the other ports are closed, anyway, so why
>spend time debugging an elaborate rule set?
>  
>

What has to be so elaborate?

    ipfw add <rulenum> deny ip from any to me in via <oif> setup

And it's generally a good idea to think about egress as well.  It's
the strategy you're using for inetd, it should probably be the way
you do your firewall.  Build the wall with the gates where you
want them instead of the other way 'round.

My $0.02,

Kevin Kinsey


More information about the freebsd-questions mailing list