Re: Learning how-to pf "right"

"Karl O. Pinc" <[email protected]> Wed, 13 May 2015 15:57:27 -0500
Newsgroups gmane.os.openbsd.pf
Message-ID <[email protected]>
On Wed, 13 May 2015 20:50:26 +0200
Dennis Steinkamp <[email protected]> wrote:

> thanks for giving a little extra advice on the anti-spoofing topic.
> Maybe you can tell me if thats still neccessary in my scenario.
> My $ext_if is a vlan interface connected to a ProCurve switch from
> where i assign one port as tagged (thats the port where the OpenBSD
> machine is connected to.)
> and one untagged port which goes to the router.
> My router is responsible for dialing the actual connection to my ISP
> so my OpenBSD box is already behind the NAT firewall of my router.
> In OpenBSD i then use Unbound as a caching nameserver which forwards
> any dns queries to the DNS Servers of my ISP.
> Of course i could set up PPPoE on OpenBsd directly but i thought
> letting the router handle it might be the better approach.
> Does antispoofing on $ext_if still makes sense for me?

If you trust your ISP or your $plasticrouter to
antispoof for you then no, you don't
need to do it yourself.  Otherwise you do.


Karl <[email protected]>
Free Software:  "You don't pay back, you pay forward."
                 -- Robert A. Heinlein