Re: Learning how-to pf "right"

"Karl O. Pinc" <[email protected]> Thu, 14 May 2015 08:28:43 -0500
Newsgroups gmane.os.openbsd.pf
Message-ID <[email protected]>
On Thu, 14 May 2015 08:51:50 -0400
Kenneth Gober <[email protected]> wrote:

> unless you're an Internet Service Provider, or you are
> participating in some kind of peering arrangement, you
> should not be accepting any unsolicited packets from
> $ext_if, never mind forwarding them back out on $ext_if.
> 
> for a typical home or business gateway, this is a sensible
> default to use:
> 
>     block in on $ext_if all
> 
> then follow that with pass rules for the specific traffic
> you want to accept.

Very good point.

I would say that there are legitimate reasons to
accept inbound traffic.  Small businesses can have
voice over IP phones, individuals often tinker with
a personal webserver, etc.





Karl <[email protected]>
Free Software:  "You don't pay back, you pay forward."
                 -- Robert A. Heinlein