Re: Learning how-to pf "right"
"Karl O. Pinc" <[email protected]> Wed, 13 May 2015 15:57:27 -0500
| Newsgroups | gmane.os.openbsd.pf |
|---|---|
| Message-ID | <[email protected]> |
On Wed, 13 May 2015 20:50:26 +0200 Dennis Steinkamp <[email protected]> wrote: > thanks for giving a little extra advice on the anti-spoofing topic. > Maybe you can tell me if thats still neccessary in my scenario. > My $ext_if is a vlan interface connected to a ProCurve switch from > where i assign one port as tagged (thats the port where the OpenBSD > machine is connected to.) > and one untagged port which goes to the router. > My router is responsible for dialing the actual connection to my ISP > so my OpenBSD box is already behind the NAT firewall of my router. > In OpenBSD i then use Unbound as a caching nameserver which forwards > any dns queries to the DNS Servers of my ISP. > Of course i could set up PPPoE on OpenBsd directly but i thought > letting the router handle it might be the better approach. > Does antispoofing on $ext_if still makes sense for me? If you trust your ISP or your $plasticrouter to antispoof for you then no, you don't need to do it yourself. Otherwise you do. Karl <[email protected]> Free Software: "You don't pay back, you pay forward." -- Robert A. Heinlein