<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: FreeBSD Setting up Firewall using IPFW</title> <atom:link href="http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/feed/" rel="self" type="application/rss+xml" /><link>http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/</link> <description>Every answer asks a more beautiful question.</description> <lastBuildDate>Fri, 10 Feb 2012 19:55:56 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>By: Fritz</title><link>http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-62275</link> <dc:creator>Fritz</dc:creator> <pubDate>Fri, 09 Sep 2011 02:01:17 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-62275</guid> <description>i need help, how do i save Save and close the file. Building a Kernel, type following commnds:?, i feel like am doing something wrong please help.</description> <content:encoded><![CDATA[<p>i need help, how do i save Save and close the file. Building a Kernel, type following commnds:?, i feel like am doing something wrong please help.</p> ]]></content:encoded> </item> <item><title>By: jason</title><link>http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-54771</link> <dc:creator>jason</dc:creator> <pubDate>Sat, 08 Jan 2011 18:53:15 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-54771</guid> <description>Dumb question... in the comments its sats that port 20 is being opened but i don&#039;t see a rule set...  since I have set up IPFW I have major pain get file listing for ftp GUI programs</description> <content:encoded><![CDATA[<p>Dumb question&#8230; in the comments its sats that port 20 is being opened but i don&#8217;t see a rule set&#8230;  since I have set up IPFW I have major pain get file listing for ftp GUI programs</p> ]]></content:encoded> </item> <item><title>By: Ivan Carrasco Q.</title><link>http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-49054</link> <dc:creator>Ivan Carrasco Q.</dc:creator> <pubDate>Fri, 27 Aug 2010 03:23:19 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-49054</guid> <description>Also modify the file /etc/sysctl.conf with:
#
net.inet.ip.fw.verbose=1
net.inet.ip.fw.verbose_limit=5
net.link.ether.bridge=1
net.link.ether.bridge_ipfw=1
net.link.ether.bridge_cfg=vr0:1,re0:1
net.link.bridge.ipfw=1
#</description> <content:encoded><![CDATA[<p>Also modify the file /etc/sysctl.conf with:</p><p> #<br
/> net.inet.ip.fw.verbose=1<br
/> net.inet.ip.fw.verbose_limit=5<br
/> net.link.ether.bridge=1<br
/> net.link.ether.bridge_ipfw=1<br
/> net.link.ether.bridge_cfg=vr0:1,re0:1<br
/> net.link.bridge.ipfw=1<br
/> #</p> ]]></content:encoded> </item> <item><title>By: Ivan Carrasco Q.</title><link>http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-49053</link> <dc:creator>Ivan Carrasco Q.</dc:creator> <pubDate>Fri, 27 Aug 2010 03:18:26 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-49053</guid> <description>just add this to /etc/rc.conf
ifconfig_re1=&quot;inet 190.93.224.XXX netmask 255.255.240.0&quot;
defaultrouter=&quot;190.93.224.1&quot;
firewall_enable=&quot;YES&quot;
firewall_script=&quot;/etc/prueba2&quot;
firewall_type=&quot;open&quot;</description> <content:encoded><![CDATA[<p>just add this to /etc/rc.conf<br
/> ifconfig_re1=&#8221;inet 190.93.224.XXX netmask 255.255.240.0&#8243;<br
/> defaultrouter=&#8221;190.93.224.1&#8243;<br
/> firewall_enable=&#8221;YES&#8221;<br
/> firewall_script=&#8221;/etc/prueba2&#8243;<br
/> firewall_type=&#8221;open&#8221;</p> ]]></content:encoded> </item> <item><title>By: Ivan Carrasco Q.</title><link>http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-48787</link> <dc:creator>Ivan Carrasco Q.</dc:creator> <pubDate>Sat, 14 Aug 2010 04:45:14 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-48787</guid> <description>Another post /etc/rc.conf
&lt;pre&gt;
#--sysinstall generated deltas -- # Wed Oct 29 22:56:03 2008
# Created: Wed Oct 29 22:56:03 2008
# Enable network daemons for user convenience.
# Please make all changes to this file, not to /etc/defaults/rc.conf.
# This file now contains just the overrides from /etc/defaults/rc.conf.
#cloned_interfaces=&quot;bridge0 bge0 bge1&quot;
#autobridge_interfaces=&quot;bridge0&quot;
#autobridge_bridge0=&quot;bge*&quot;
#ifconfig_bridge0=&quot;10.192.0.69 netmask 0xffff0000&quot;
cloned_interfaces=&quot;vlan24090 vlan24091 vlan3960 vlan3961 vlan19030 vlan19031 vlan19040 vlan19041&quot;
ifconfig_bge0=&quot;up&quot;
ifconfig_bge1=&quot;up&quot;
ifconfig_vlan24090=&quot;vlan 2409 vlandev bge0&quot;
ifconfig_vlan3960=&quot;vlan 396 vlandev bge0&quot;
ifconfig_vlan24091=&quot;vlan 2409 vlandev bge1&quot;
ifconfig_vlan3961=&quot;vlan 396 vlandev bge1&quot;
ifconfig_vlan19040=&quot;vlan 1904 vlandev bge0&quot;
ifconfig_vlan19030=&quot;vlan 1903 vlandev bge0&quot;
ifconfig_vlan19041=&quot;vlan 1904 vlandev bge1&quot;
ifconfig_vlan19031=&quot;vlan 1903 vlandev bge1&quot;
cloned_interfaces=&quot;bridge0 vlan24090 vlan24091 bridge1 vlan3960 vlan3961 bridge2 vlan19030 vlan19041 bridge3 vlan19040 vlan19041&quot;
ifconfig_bridge0=&quot;addm vlan24090 addm vlan24091 up&quot;
ifconfig_bridge1=&quot;addm vlan3960 addm vlan3961 up&quot;
ifconfig_bridge2=&quot;addm vlan19030 addm vlan19031 up&quot;
ifconfig_bridge3=&quot;addm vlan19040 addm vlan19041 up&quot;
ifconfig_bge0=&quot;10.192.0.69 netmask 0xffff0000&quot;
linux_enable=&quot;YES&quot;
sshd_enable=&quot;YES&quot;
&lt;/pre&gt;</description> <content:encoded><![CDATA[<p>Another post /etc/rc.conf</p><pre>
#--sysinstall generated deltas -- # Wed Oct 29 22:56:03 2008
# Created: Wed Oct 29 22:56:03 2008
# Enable network daemons for user convenience.
# Please make all changes to this file, not to /etc/defaults/rc.conf.
# This file now contains just the overrides from /etc/defaults/rc.conf.
#cloned_interfaces="bridge0 bge0 bge1"
#autobridge_interfaces="bridge0"
#autobridge_bridge0="bge*"
#ifconfig_bridge0="10.192.0.69 netmask 0xffff0000"
cloned_interfaces="vlan24090 vlan24091 vlan3960 vlan3961 vlan19030 vlan19031 vlan19040 vlan19041"
ifconfig_bge0="up"
ifconfig_bge1="up"
ifconfig_vlan24090="vlan 2409 vlandev bge0"
ifconfig_vlan3960="vlan 396 vlandev bge0"
ifconfig_vlan24091="vlan 2409 vlandev bge1"
ifconfig_vlan3961="vlan 396 vlandev bge1"
ifconfig_vlan19040="vlan 1904 vlandev bge0"
ifconfig_vlan19030="vlan 1903 vlandev bge0"
ifconfig_vlan19041="vlan 1904 vlandev bge1"
ifconfig_vlan19031="vlan 1903 vlandev bge1"
cloned_interfaces="bridge0 vlan24090 vlan24091 bridge1 vlan3960 vlan3961 bridge2 vlan19030 vlan19041 bridge3 vlan19040 vlan19041"
ifconfig_bridge0="addm vlan24090 addm vlan24091 up"
ifconfig_bridge1="addm vlan3960 addm vlan3961 up"
ifconfig_bridge2="addm vlan19030 addm vlan19031 up"
ifconfig_bridge3="addm vlan19040 addm vlan19041 up"
ifconfig_bge0="10.192.0.69 netmask 0xffff0000"
linux_enable="YES"
sshd_enable="YES"
</pre>]]></content:encoded> </item> <item><title>By: Iván Carrasco Q.</title><link>http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-48703</link> <dc:creator>Iván Carrasco Q.</dc:creator> <pubDate>Mon, 09 Aug 2010 20:52:53 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-48703</guid> <description>I just wanted to share in this post my script. I have configured a machine working as a Traffic Shaper with 4 kind of clients, up/down, national/international bw, and also unlimited clients:
&lt;pre&gt;
#!/bin/sh
fw=&quot;/sbin/ipfw&quot;
#Default traffic
BWNAC=&quot;2048KBit/s&quot;
BWINT=&quot;1024KBit/s&quot;
#Planes
BW1NAC=&quot;600KBit/s&quot;
BW1INT=&quot;250KBit/s&quot;
BW2NAC=&quot;1024KBit/s&quot;
BW2INT=&quot;450KBit/s&quot;
BW3NAC=&quot;2048KBit/s&quot;
BW3INT=&quot;950KBit/s&quot;
##IPs
#IP600 con plan BW1
IP600=&quot;{ 190.93.239.0/24 }&quot;
#IP1024 con plan BW2
IP1024=&quot;{ 190.93.225.0/24 or 190.93.226.0/23 or 190.93.228.0/22 or 190.93.232.0/23 or 190.93.234.0/24 or 200.73.215.0{0-124} or 200.73.213.0{1-254} or 200.73.214.0{0-254} or 200.73.212.0{100-255} }&quot;
#IP2048 con plan BW3
IP2048=&quot;{ 190.93.235.0/24 or 190.93.236.0/23 or 190.93.238.0/24 or 200.73.215.0{125-254} }&quot;
IPNOCUT=&quot;{ 190.93.224.0/24 or 200.73.208.0{1-69} }&quot;
$fw -f flush
$fw -f pipe flush
$fw -f queue flush
$fw enable one_pass
$fw add 10 check-state
$fw add 100 allow ip from any to any via lo0
$fw add 200 allow ip from any to 127.0.0.1/8
$fw add 300 allow ip from 127.0.0.1/8 to any
$fw add 540 deny ip from any to any frag in
$fw add 600 allow all from ${IPNOCUT} to any
$fw add 700 allow all from any to ${IPNOCUT}
$fw pipe 1 config buckets 2048 mask src-ip 0xffffffff bw ${BWNAC}
$fw pipe 2 config buckets 2048 mask dst-ip 0xffffffff bw ${BWNAC}
$fw pipe 3 config buckets 2048 mask src-ip 0xffffffff bw ${BWNAC}
$fw pipe 4 config buckets 2048 mask dst-ip 0xffffffff bw ${BWNAC}
$fw pipe 7 config buckets 2048 mask src-ip 0xffffffff bw ${BWINT}
$fw pipe 8 config buckets 2048 mask dst-ip 0xffffffff bw ${BWINT}
$fw pipe 9 config buckets 2048 mask src-ip 0xffffffff bw ${BWNAC}
$fw pipe 10 config buckets 2048 mask dst-ip 0xffffffff bw ${BWNAC}
#
$fw pipe 21 config buckets 2048 mask src-ip 0xffffffff bw ${BW1NAC}
$fw pipe 22 config buckets 2048 mask dst-ip 0xffffffff bw ${BW1NAC}
$fw pipe 23 config buckets 2048 mask src-ip 0xffffffff bw ${BW1INT}
$fw pipe 24 config buckets 2048 mask dst-ip 0xffffffff bw ${BW1INT}
#
$fw pipe 31 config buckets 2048 mask src-ip 0xffffffff bw ${BW2NAC}
$fw pipe 32 config buckets 2048 mask dst-ip 0xffffffff bw ${BW2NAC}
$fw pipe 33 config buckets 2048 mask src-ip 0xffffffff bw ${BW2INT}
$fw pipe 34 config buckets 2048 mask dst-ip 0xffffffff bw ${BW2INT}
#
$fw pipe 41 config buckets 2048 mask src-ip 0xffffffff bw ${BW3NAC}
$fw pipe 42 config buckets 2048 mask dst-ip 0xffffffff bw ${BW3NAC}
$fw pipe 43 config buckets 2048 mask src-ip 0xffffffff bw ${BW3INT}
$fw pipe 44 config buckets 2048 mask dst-ip 0xffffffff bw ${BW3INT}
#
$fw add 1460 allow all from $IPNOCUT to any out xmit bridge0
$fw add 1480 allow all from any to $IPNOCUT in recv bridge0
$fw add 1560 allow all from $IPNOCUT to any out xmit bridge1
$fw add 1580 allow all  from any to $IPNOCUT in recv bridge1
#
####### 600 Permisos por Bridge #################################
$fw add 4660 pipe 21 all from ${IP600} to any out xmit bridge0
$fw add 4680 pipe 22 all from any to ${IP600} in recv bridge0
$fw add 4760 pipe 21 all from ${IP600} to any out xmit bridge1
$fw add 4780 pipe 22 all  from any to ${IP600} in recv bridge1
####### 1024 Permisos por Bridge #################################
$fw add 4660 pipe 31 all from ${IP1024} to any out xmit bridge0
$fw add 4680 pipe 32 all from any to ${IP1024} in recv bridge0
$fw add 4760 pipe 31 all from ${IP1024} to any out xmit bridge1
$fw add 4780 pipe 32 all  from any to ${IP1024} in recv bridge1
####### 2048 Permisos por Bridge #################################
$fw add 4660 pipe 41 all from ${IP2048} to any out xmit bridge0
$fw add 4680 pipe 42 all from any to ${IP2048} in recv bridge0
$fw add 4760 pipe 41 all from ${IP2048} to any out xmit bridge1
$fw add 4780 pipe 42 all  from any to ${IP2048} in recv bridge1
#
$fw add 4860 pipe 3 all from any to any out xmit bridge0
$fw add 4880 pipe 4 all from any to any in recv bridge0
$fw add 4960 pipe 3 all from any to any out xmit bridge1
$fw add 4980 pipe 4 all  from any to any in recv bridge1
############# 600 Permisos por Interfaz  ######################
$fw add 24260 pipe 21 all from ${IP600} to any in via bge0
$fw add 24270 pipe 22 all from any to ${IP600} out via bge0
$fw add 24280 pipe 22 all from ${IP600} to any in via bge1
$fw add 24290 pipe 21 all from any to ${IP600} out via bge1
############# 1024 Permisos por Interfaz  ######################
$fw add 24260 pipe 31 all from ${IP1024} to any in via bge0
$fw add 24270 pipe 32 all from any to ${IP1024} out via bge0
$fw add 24280 pipe 32 all from ${IP1024} to any in via bge1
$fw add 24290 pipe 31 all from any to ${IP1024} out via bge1
############# 2048 Permisos por Interfaz  ######################
$fw add 24260 pipe 41 all from ${IP2048} to any in via bge0
$fw add 24270 pipe 42 all from any to ${IP2048} out via bge0
$fw add 24280 pipe 42 all from ${IP2048} to any in via bge1
$fw add 24290 pipe 41 all from any to ${IP2048} out via bge1
#
$fw add 25260 pipe 1 all from any to any in via bge0
$fw add 25270 pipe 2 all from any to any out via bge0
$fw add 25280 pipe 2 all from any to any in via bge1
$fw add 25290 pipe 1 all from any to any out via bge1
############# 600 Permisos por Vlan Internacional  ############
$fw add 35260 pipe 24 all from ${IP600} to any out via vlan24090
$fw add 35270 pipe 23 all from any to ${IP600} in via vlan24090
$fw add 35280 pipe 24 all from ${IP600} to any in via vlan24091
$fw add 35290 pipe 23 all from any to ${IP600} out via vlan24091
############# 1024 Permisos por Vlan Internacional  ############
$fw add 35260 pipe 34 all from ${IP1024} to any out via vlan24090
$fw add 35270 pipe 33 all from any to ${IP1024} in via vlan24090
$fw add 35280 pipe 34 all from ${IP1024} to any in via vlan24091
$fw add 35290 pipe 33 all from any to ${IP1024} out via vlan24091
############# 2048 Permisos por Vlan Internacional  ############
$fw add 35260 pipe 44 all from ${IP2048} to any out via vlan24090
$fw add 35270 pipe 43 all from any to ${IP2048} in via vlan24090
$fw add 35280 pipe 44 all from ${IP2048} to any in via vlan24091
$fw add 35290 pipe 43 all from any to ${IP2048} out via vlan24091
#
$fw add 36260 pipe 7 all from any to any in via vlan24090
$fw add 36270 pipe 8 all from any to any out via vlan24090
$fw add 36280 pipe 8 all from any to any in via vlan24091
$fw add 36290 pipe 7 all from any to any out via vlan24091
############# 600 Permisos por Vlan nacional  #################
$fw add 47260 pipe 21 all from ${IP600} to any out via vlan3960
$fw add 47270 pipe 22 all from any to ${IP600} in  via vlan3960
$fw add 47280 pipe 22 all from ${IP600} to any in via vlan3961
$fw add 47290 pipe 21 all from any to ${IP600} out via vlan3961
############# 1024 Permisos por Vlan nacional  #################
$fw add 47260 pipe 31 all from ${IP1024} to any out via vlan3960
$fw add 47270 pipe 32 all from any to ${IP1024} in  via vlan3960
$fw add 47280 pipe 32 all from ${IP1024} to any in via vlan3961
$fw add 47290 pipe 31 all from any to ${IP1024} out via vlan3961
############# 2048 Permisos por Vlan nacional  #################
$fw add 47260 pipe 41 all from ${IP2048} to any out via vlan3960
$fw add 47270 pipe 42 all from any to ${IP2048} in  via vlan3960
$fw add 47280 pipe 42 all from ${IP2048} to any in via vlan3961
$fw add 47290 pipe 41 all from any to ${IP2048} out via vlan3961
#
$fw add 47260 pipe 10 all from any to any in via vlan3960
$fw add 47270 pipe 9 all from any to any out via vlan3960
$fw add 47280 pipe 10 all from any to any in via vlan3961
$fw add 47290 pipe 9 all from any to any out via vlan3961
#
$fw add 60000 allow ip from any to any
#
##################################################
&lt;/pre&gt;</description> <content:encoded><![CDATA[<p>I just wanted to share in this post my script. I have configured a machine working as a Traffic Shaper with 4 kind of clients, up/down, national/international bw, and also unlimited clients:</p><pre>
#!/bin/sh
fw="/sbin/ipfw"
#Default traffic
BWNAC="2048KBit/s"
BWINT="1024KBit/s"
#Planes
BW1NAC="600KBit/s"
BW1INT="250KBit/s"
BW2NAC="1024KBit/s"
BW2INT="450KBit/s"
BW3NAC="2048KBit/s"
BW3INT="950KBit/s"
##IPs
#IP600 con plan BW1
IP600="{ 190.93.239.0/24 }"
#IP1024 con plan BW2
IP1024="{ 190.93.225.0/24 or 190.93.226.0/23 or 190.93.228.0/22 or 190.93.232.0/23 or 190.93.234.0/24 or 200.73.215.0{0-124} or 200.73.213.0{1-254} or 200.73.214.0{0-254} or 200.73.212.0{100-255} }"
#IP2048 con plan BW3
IP2048="{ 190.93.235.0/24 or 190.93.236.0/23 or 190.93.238.0/24 or 200.73.215.0{125-254} }"
IPNOCUT="{ 190.93.224.0/24 or 200.73.208.0{1-69} }"
$fw -f flush
$fw -f pipe flush
$fw -f queue flush
$fw enable one_pass
$fw add 10 check-state
$fw add 100 allow ip from any to any via lo0
$fw add 200 allow ip from any to 127.0.0.1/8
$fw add 300 allow ip from 127.0.0.1/8 to any
$fw add 540 deny ip from any to any frag in
$fw add 600 allow all from ${IPNOCUT} to any
$fw add 700 allow all from any to ${IPNOCUT}
$fw pipe 1 config buckets 2048 mask src-ip 0xffffffff bw ${BWNAC}
$fw pipe 2 config buckets 2048 mask dst-ip 0xffffffff bw ${BWNAC}
$fw pipe 3 config buckets 2048 mask src-ip 0xffffffff bw ${BWNAC}
$fw pipe 4 config buckets 2048 mask dst-ip 0xffffffff bw ${BWNAC}
$fw pipe 7 config buckets 2048 mask src-ip 0xffffffff bw ${BWINT}
$fw pipe 8 config buckets 2048 mask dst-ip 0xffffffff bw ${BWINT}
$fw pipe 9 config buckets 2048 mask src-ip 0xffffffff bw ${BWNAC}
$fw pipe 10 config buckets 2048 mask dst-ip 0xffffffff bw ${BWNAC}
#
$fw pipe 21 config buckets 2048 mask src-ip 0xffffffff bw ${BW1NAC}
$fw pipe 22 config buckets 2048 mask dst-ip 0xffffffff bw ${BW1NAC}
$fw pipe 23 config buckets 2048 mask src-ip 0xffffffff bw ${BW1INT}
$fw pipe 24 config buckets 2048 mask dst-ip 0xffffffff bw ${BW1INT}
#
$fw pipe 31 config buckets 2048 mask src-ip 0xffffffff bw ${BW2NAC}
$fw pipe 32 config buckets 2048 mask dst-ip 0xffffffff bw ${BW2NAC}
$fw pipe 33 config buckets 2048 mask src-ip 0xffffffff bw ${BW2INT}
$fw pipe 34 config buckets 2048 mask dst-ip 0xffffffff bw ${BW2INT}
#
$fw pipe 41 config buckets 2048 mask src-ip 0xffffffff bw ${BW3NAC}
$fw pipe 42 config buckets 2048 mask dst-ip 0xffffffff bw ${BW3NAC}
$fw pipe 43 config buckets 2048 mask src-ip 0xffffffff bw ${BW3INT}
$fw pipe 44 config buckets 2048 mask dst-ip 0xffffffff bw ${BW3INT}
#
$fw add 1460 allow all from $IPNOCUT to any out xmit bridge0
$fw add 1480 allow all from any to $IPNOCUT in recv bridge0
$fw add 1560 allow all from $IPNOCUT to any out xmit bridge1
$fw add 1580 allow all  from any to $IPNOCUT in recv bridge1
#
####### 600 Permisos por Bridge #################################
$fw add 4660 pipe 21 all from ${IP600} to any out xmit bridge0
$fw add 4680 pipe 22 all from any to ${IP600} in recv bridge0
$fw add 4760 pipe 21 all from ${IP600} to any out xmit bridge1
$fw add 4780 pipe 22 all  from any to ${IP600} in recv bridge1
####### 1024 Permisos por Bridge #################################
$fw add 4660 pipe 31 all from ${IP1024} to any out xmit bridge0
$fw add 4680 pipe 32 all from any to ${IP1024} in recv bridge0
$fw add 4760 pipe 31 all from ${IP1024} to any out xmit bridge1
$fw add 4780 pipe 32 all  from any to ${IP1024} in recv bridge1
####### 2048 Permisos por Bridge #################################
$fw add 4660 pipe 41 all from ${IP2048} to any out xmit bridge0
$fw add 4680 pipe 42 all from any to ${IP2048} in recv bridge0
$fw add 4760 pipe 41 all from ${IP2048} to any out xmit bridge1
$fw add 4780 pipe 42 all  from any to ${IP2048} in recv bridge1
#
$fw add 4860 pipe 3 all from any to any out xmit bridge0
$fw add 4880 pipe 4 all from any to any in recv bridge0
$fw add 4960 pipe 3 all from any to any out xmit bridge1
$fw add 4980 pipe 4 all  from any to any in recv bridge1
############# 600 Permisos por Interfaz  ######################
$fw add 24260 pipe 21 all from ${IP600} to any in via bge0
$fw add 24270 pipe 22 all from any to ${IP600} out via bge0
$fw add 24280 pipe 22 all from ${IP600} to any in via bge1
$fw add 24290 pipe 21 all from any to ${IP600} out via bge1
############# 1024 Permisos por Interfaz  ######################
$fw add 24260 pipe 31 all from ${IP1024} to any in via bge0
$fw add 24270 pipe 32 all from any to ${IP1024} out via bge0
$fw add 24280 pipe 32 all from ${IP1024} to any in via bge1
$fw add 24290 pipe 31 all from any to ${IP1024} out via bge1
############# 2048 Permisos por Interfaz  ######################
$fw add 24260 pipe 41 all from ${IP2048} to any in via bge0
$fw add 24270 pipe 42 all from any to ${IP2048} out via bge0
$fw add 24280 pipe 42 all from ${IP2048} to any in via bge1
$fw add 24290 pipe 41 all from any to ${IP2048} out via bge1
#
$fw add 25260 pipe 1 all from any to any in via bge0
$fw add 25270 pipe 2 all from any to any out via bge0
$fw add 25280 pipe 2 all from any to any in via bge1
$fw add 25290 pipe 1 all from any to any out via bge1
############# 600 Permisos por Vlan Internacional  ############
$fw add 35260 pipe 24 all from ${IP600} to any out via vlan24090
$fw add 35270 pipe 23 all from any to ${IP600} in via vlan24090
$fw add 35280 pipe 24 all from ${IP600} to any in via vlan24091
$fw add 35290 pipe 23 all from any to ${IP600} out via vlan24091
############# 1024 Permisos por Vlan Internacional  ############
$fw add 35260 pipe 34 all from ${IP1024} to any out via vlan24090
$fw add 35270 pipe 33 all from any to ${IP1024} in via vlan24090
$fw add 35280 pipe 34 all from ${IP1024} to any in via vlan24091
$fw add 35290 pipe 33 all from any to ${IP1024} out via vlan24091
############# 2048 Permisos por Vlan Internacional  ############
$fw add 35260 pipe 44 all from ${IP2048} to any out via vlan24090
$fw add 35270 pipe 43 all from any to ${IP2048} in via vlan24090
$fw add 35280 pipe 44 all from ${IP2048} to any in via vlan24091
$fw add 35290 pipe 43 all from any to ${IP2048} out via vlan24091
#
$fw add 36260 pipe 7 all from any to any in via vlan24090
$fw add 36270 pipe 8 all from any to any out via vlan24090
$fw add 36280 pipe 8 all from any to any in via vlan24091
$fw add 36290 pipe 7 all from any to any out via vlan24091
############# 600 Permisos por Vlan nacional  #################
$fw add 47260 pipe 21 all from ${IP600} to any out via vlan3960
$fw add 47270 pipe 22 all from any to ${IP600} in  via vlan3960
$fw add 47280 pipe 22 all from ${IP600} to any in via vlan3961
$fw add 47290 pipe 21 all from any to ${IP600} out via vlan3961
############# 1024 Permisos por Vlan nacional  #################
$fw add 47260 pipe 31 all from ${IP1024} to any out via vlan3960
$fw add 47270 pipe 32 all from any to ${IP1024} in  via vlan3960
$fw add 47280 pipe 32 all from ${IP1024} to any in via vlan3961
$fw add 47290 pipe 31 all from any to ${IP1024} out via vlan3961
############# 2048 Permisos por Vlan nacional  #################
$fw add 47260 pipe 41 all from ${IP2048} to any out via vlan3960
$fw add 47270 pipe 42 all from any to ${IP2048} in  via vlan3960
$fw add 47280 pipe 42 all from ${IP2048} to any in via vlan3961
$fw add 47290 pipe 41 all from any to ${IP2048} out via vlan3961
#
$fw add 47260 pipe 10 all from any to any in via vlan3960
$fw add 47270 pipe 9 all from any to any out via vlan3960
$fw add 47280 pipe 10 all from any to any in via vlan3961
$fw add 47290 pipe 9 all from any to any out via vlan3961
#
$fw add 60000 allow ip from any to any
#
##################################################
</pre>]]></content:encoded> </item> <item><title>By: martin</title><link>http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-45835</link> <dc:creator>martin</dc:creator> <pubDate>Fri, 05 Feb 2010 03:59:26 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-45835</guid> <description>Have added the DEFAULT_TO_ACCEPT option and removed /etc/rc.conf enables and am still locket out.
Outstanding article.</description> <content:encoded><![CDATA[<p>Have added the DEFAULT_TO_ACCEPT option and removed /etc/rc.conf enables and am still locket out.<br
/> Outstanding article.</p> ]]></content:encoded> </item> <item><title>By: sam</title><link>http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-43285</link> <dc:creator>sam</dc:creator> <pubDate>Fri, 21 Aug 2009 01:48:29 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-43285</guid> <description>if you dont add DEFAULT_TO_ACCEPT and do not already have a firewall script in place, when you reboot your box the default will be to deny ALL, therefore if your box is not local you may have an issue =)</description> <content:encoded><![CDATA[<p>if you dont add DEFAULT_TO_ACCEPT and do not already have a firewall script in place, when you reboot your box the default will be to deny ALL, therefore if your box is not local you may have an issue =)</p> ]]></content:encoded> </item> <item><title>By: Patric Falinder</title><link>http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-41578</link> <dc:creator>Patric Falinder</dc:creator> <pubDate>Tue, 12 May 2009 12:42:15 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-41578</guid> <description>How do I modify the script to NAT my traffic from my OpenVPN interface tun0 to my external interface vr0 (it has a direct connection to internet, no router between)?
OpenVPN----&gt;vr0----&gt;INTERNET</description> <content:encoded><![CDATA[<p>How do I modify the script to NAT my traffic from my OpenVPN interface tun0 to my external interface vr0 (it has a direct connection to internet, no router between)?</p><p>OpenVPN&#8212;-&gt;vr0&#8212;-&gt;INTERNET</p> ]]></content:encoded> </item> <item><title>By: Alan</title><link>http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-39985</link> <dc:creator>Alan</dc:creator> <pubDate>Sat, 24 Jan 2009 15:26:32 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-39985</guid> <description>Thank you man!
This is wonderful! I make this process and ther works perfect.
Thank you again!
Sorry for my bad english.
[ ]&#039;s</description> <content:encoded><![CDATA[<p>Thank you man!</p><p>This is wonderful! I make this process and ther works perfect.</p><p>Thank you again!</p><p>Sorry for my bad english.</p><p>[ ]&#8216;s</p> ]]></content:encoded> </item> <item><title>By: Emman</title><link>http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-39801</link> <dc:creator>Emman</dc:creator> <pubDate>Mon, 12 Jan 2009 07:57:43 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-39801</guid> <description>Nice firewall, how about blocking by means of MC Address, I set-up a proxy server
and allow only specific IP&#039;s, but the problem is that some users knows how to change
their IP address and knows what are the IP&#039;s that are allowed to surf the Internet. So
I think blocking by means of MC Address solve my problem here in out company.
Can you help me?
Thank you and more power.</description> <content:encoded><![CDATA[<p>Nice firewall, how about blocking by means of MC Address, I set-up a proxy server<br
/> and allow only specific IP&#8217;s, but the problem is that some users knows how to change<br
/> their IP address and knows what are the IP&#8217;s that are allowed to surf the Internet. So<br
/> I think blocking by means of MC Address solve my problem here in out company.<br
/> Can you help me?</p><p>Thank you and more power.</p> ]]></content:encoded> </item> <item><title>By: boom</title><link>http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-39666</link> <dc:creator>boom</dc:creator> <pubDate>Wed, 31 Dec 2008 08:21:08 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-39666</guid> <description>locking myself out</description> <content:encoded><![CDATA[<p>locking myself out</p> ]]></content:encoded> </item> <item><title>By: Real FreeBSD Tips &#187; Stopping SSH &#38; FTP brute force attacks with IPFW</title><link>http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-39382</link> <dc:creator>Real FreeBSD Tips &#187; Stopping SSH &#38; FTP brute force attacks with IPFW</dc:creator> <pubDate>Sun, 07 Dec 2008 00:17:48 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-39382</guid> <description>[...] then IPFW is not enabled. You can learn how to enable it over here. [...]</description> <content:encoded><![CDATA[<p>[...] then IPFW is not enabled. You can learn how to enable it over here. [...]</p> ]]></content:encoded> </item> <item><title>By: sara</title><link>http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-38996</link> <dc:creator>sara</dc:creator> <pubDate>Fri, 17 Oct 2008 10:49:38 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-38996</guid> <description>more useful..
Thanks a lot</description> <content:encoded><![CDATA[<p>more useful..</p><p>Thanks a lot</p> ]]></content:encoded> </item> <item><title>By: Njuki</title><link>http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-38263</link> <dc:creator>Njuki</dc:creator> <pubDate>Wed, 09 Jul 2008 12:53:06 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-38263</guid> <description>i think you should add, before the reboot
options		IPFIREWALL_DEFAULT_TO_ACCEPT
When appending options for the kernel, i followed the above steps and realized i could not log in remotely to the box i was building a firewall after the reboot.</description> <content:encoded><![CDATA[<p>i think you should add, before the reboot</p><p>options		IPFIREWALL_DEFAULT_TO_ACCEPT</p><p>When appending options for the kernel, i followed the above steps and realized i could not log in remotely to the box i was building a firewall after the reboot.</p> ]]></content:encoded> </item> <item><title>By: relch</title><link>http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-37779</link> <dc:creator>relch</dc:creator> <pubDate>Thu, 17 Apr 2008 03:46:12 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-37779</guid> <description>hi! I need help regarding ipfw. i&#039;m a newbie to freebsd. I want my freebsd to be the gateway of my WLAN to the internet. I also want to authenticate each user through a database. Can anyone help me?
I just need it for my case study in school.
here&#039;s my email for those who want to help:
relch2k7@yahoo.com
thanks!</description> <content:encoded><![CDATA[<p>hi! I need help regarding ipfw. i&#8217;m a newbie to freebsd. I want my freebsd to be the gateway of my WLAN to the internet. I also want to authenticate each user through a database. Can anyone help me?<br
/> I just need it for my case study in school.</p><p>here&#8217;s my email for those who want to help:</p><p><a
href="mailto:relch2k7@yahoo.com">relch2k7@yahoo.com</a></p><p>thanks!</p> ]]></content:encoded> </item> <item><title>By: Satyesh Banavali</title><link>http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-37446</link> <dc:creator>Satyesh Banavali</dc:creator> <pubDate>Sun, 10 Feb 2008 09:13:22 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-37446</guid> <description>I tried both the scripts. Both the scripts bolck http requests and the bsd cannot resolve any DNS queries once they are executed. The moment I open up the firewall everything goes through.
I could not achieve browsing with the script in place. Maybe I am doing something wrong.....
My public IP is 81.155.30.2 and my internal Network is 172.16.0.0
FreeBSD is 6.10</description> <content:encoded><![CDATA[<p>I tried both the scripts. Both the scripts bolck http requests and the bsd cannot resolve any DNS queries once they are executed. The moment I open up the firewall everything goes through.</p><p>I could not achieve browsing with the script in place. Maybe I am doing something wrong&#8230;..</p><p>My public IP is 81.155.30.2 and my internal Network is 172.16.0.0</p><p>FreeBSD is 6.10</p> ]]></content:encoded> </item> <item><title>By: Fred</title><link>http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-37001</link> <dc:creator>Fred</dc:creator> <pubDate>Sat, 10 Nov 2007 21:11:41 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-37001</guid> <description>What about blocking Nmap?
01100 deny ip from any to any ipoptions rr
01110 deny ip from any to any ipoptions ts
01120 deny ip from any to any ipoptions lsrr
01130 deny ip from any to any ipoptions ssrr
01140 deny tcp from any to any tcpflags syn,fin
01150 deny tcp from any to any tcpflags syn,rst</description> <content:encoded><![CDATA[<p>What about blocking Nmap?</p><p>01100 deny ip from any to any ipoptions rr<br
/> 01110 deny ip from any to any ipoptions ts<br
/> 01120 deny ip from any to any ipoptions lsrr<br
/> 01130 deny ip from any to any ipoptions ssrr<br
/> 01140 deny tcp from any to any tcpflags syn,fin<br
/> 01150 deny tcp from any to any tcpflags syn,rst</p> ]]></content:encoded> </item> <item><title>By: Vladimir Tserijemiwtz</title><link>http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-36968</link> <dc:creator>Vladimir Tserijemiwtz</dc:creator> <pubDate>Sat, 27 Oct 2007 23:22:57 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-36968</guid> <description>Please make note that you can run IPFW &amp; NATD on FreeBSD-6.x without recompiling anything into your computer. The docs keep making reference that you will need to recompile your kernel if you want NATD. I have my system running and it&#039;s using the GENERIC kernel. Both IPFW and NATD work just fine without recompiling the kernel.
FreeBSD docs are often out of date and can send you down the wrong road.</description> <content:encoded><![CDATA[<p>Please make note that you can run IPFW &amp; NATD on FreeBSD-6.x without recompiling anything into your computer. The docs keep making reference that you will need to recompile your kernel if you want NATD. I have my system running and it&#8217;s using the GENERIC kernel. Both IPFW and NATD work just fine without recompiling the kernel.</p><p>FreeBSD docs are often out of date and can send you down the wrong road.</p> ]]></content:encoded> </item> <item><title>By: aunk</title><link>http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-36738</link> <dc:creator>aunk</dc:creator> <pubDate>Tue, 14 Aug 2007 15:06:07 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/howto-setup-freebsd-ipfw-firewall/#comment-36738</guid> <description>hi all, i want to ask
fbsdguru, is you ip 192.168.1.5 facing the internet?  mine have 2 ether, 1 assigned ip from NAP, and 1 assigned ip for main router of my network (ISP). is your script compatible for my network design? assume that ether which facing public is dc0 and ether for main router is vr0, any suggestion for best firewall on my machine?
thanks before, sorry for bad english.</description> <content:encoded><![CDATA[<p>hi all, i want to ask</p><p>fbsdguru, is you ip 192.168.1.5 facing the internet?  mine have 2 ether, 1 assigned ip from NAP, and 1 assigned ip for main router of my network (ISP). is your script compatible for my network design? assume that ether which facing public is dc0 and ether for main router is vr0, any suggestion for best firewall on my machine?</p><p>thanks before, sorry for bad english.</p> ]]></content:encoded> </item> </channel> </rss>
