Questions tagged [pf]
pf (Packet Filter) is the TCP/IP packet filtering firewall subsystem on BSD systems.
89 questions
0 votes
1 answer
126 views
Can't see blocked ssh connection using pf in FreeBSD
On FreeBSD I'm trying to block bruteforce attempts via ssh with pf on port 22 using this rule: table <bruteforce> persist pass log inet proto tcp from any to any port 22 flags S/SA keep state \ ...
0 votes
1 answer
158 views
openbsd: Allow access to a certain interface only to root
I have several interfaces, one of them urndis0 is an external USB modem. I want that only root could use it (i.e send packages through it), while other users would be unable to do so. How to do it?
1 vote
1 answer
97 views
PF Firewall: Restrict Access to Other Ports Only for Clients with Active SSH Connections
I previously worked with a large organization that employed BSD for secure control over public access to their internal network. The approach involved users establishing authenticated SSH connections ...
1 vote
0 answers
123 views
Can I prevent access to a port to a specific process? (MacOS)
I have a handful of kafka brokers running locally on my laptop and I'd like to "cut the network" between 2 brokers to test a few things. Is it possible? I'm on a Mac. I see that iptables was ...
0 votes
1 answer
2k views
FreeBSD: PF / pf.conf forwarding rule between interfaces
I would like to set up a simple forward rule (not port forward!) on FreeBSD 12.3 that filters based on received-on interface and going-out-on interface. IP networks should not be part of the rule as ...
4 votes
1 answer
603 views
Should changing firewall settings to block all interrupt ongoing ssh session
Suppose I am logged into a server via ssh. While in the session, I change the firewall config to block all traffic. When I tried this previously with FreeBSD and pf, the current connection was broken. ...
2 votes
1 answer
585 views
Isssues forwarding port / Nat on openbsd
I am unable to make port 80 available on the WAN and I am not sure why. My setup is just my home network acting as the wan and my ‘lab’ as the lan. Wan 192.168.0.0/24 and lan is 192.168.5.0/24. Router ...
3 votes
0 answers
561 views
EdgeRouter Lite OpenBSD traffic routing limits [closed]
When routing traffic between (virtual) interfaces on Ubiquiti EdgeRouter Lite it is hitting some sort of limit. I'd like to get some help to determine what sort of limit is that and how it can be ...
-1 votes
1 answer
2k views
Bridging Ethernet Interface on OpenBSD and Other Problems
I am currently setting up an OpenBSD firewall, router, and dns server. I've been following various guides online with the bulk of my configuration coming from the OpenBSD site and the pf configuration ...
0 votes
1 answer
236 views
Filtering the ICMP packets on Solaris using IP-addresses from the table
I'm currently working with Packet Filter on Solaris machine, trying to create a rule that would filter out all ICMP packets of particular type and code. Here is my rule line: block out quick proto ...
0 votes
1 answer
893 views
macos monterey: PF load anchor syntax error
I am trying to make a NAT interface to connect tap0 to the internet for QEMU. So far I've made a bridge and connected tap0 to it: sudo ifconfig bridge1 create sudo ifconfig bridge1 addm tap0 sudo ...
1 vote
2 answers
1k views
Openbsd wireguard to wireguard
I build a server (vps) which play the role of my gateway. My whole personal network is connected behind through wireguard. Every think works well, I follow more or less https://openbsdrouterguide.net ...
0 votes
0 answers
690 views
Can't ping to OpenBSD router's globally routable IPv6 addresses
My router's IP address layout is as follows, anonymized to protect my network's privacy: 11.22.33.44 IPv4 WAN address 192.168.42.1 IPv4 LAN ...
1 vote
1 answer
95 views
PF states table give preoccupant results
I freshly install openBSD on a VPS. It is my first time. I did nothing but check the firewall setup, say pf. I ran pfctl -sa and it show all tcp IP0:22 <- IP1:rnd ESTABLISHED:ESTABLISHED all tcp ...
0 votes
1 answer
103 views
pf - time of day filter
I'm using pf: https://www.openbsd.org/faq/pf/config.html, as a firewall on my router. I would like to implement a time of day filter in pf if that is possible so that I wouldn't need to script it ...