Re: Learning how-to pf "right"
"Karl O. Pinc" <[email protected]> Thu, 14 May 2015 08:28:43 -0500
| Newsgroups | gmane.os.openbsd.pf |
|---|---|
| Message-ID | <[email protected]> |
On Thu, 14 May 2015 08:51:50 -0400 Kenneth Gober <[email protected]> wrote: > unless you're an Internet Service Provider, or you are > participating in some kind of peering arrangement, you > should not be accepting any unsolicited packets from > $ext_if, never mind forwarding them back out on $ext_if. > > for a typical home or business gateway, this is a sensible > default to use: > > block in on $ext_if all > > then follow that with pass rules for the specific traffic > you want to accept. Very good point. I would say that there are legitimate reasons to accept inbound traffic. Small businesses can have voice over IP phones, individuals often tinker with a personal webserver, etc. Karl <[email protected]> Free Software: "You don't pay back, you pay forward." -- Robert A. Heinlein