Page MenuHomeDevCentral

Enable pf firewall
ClosedPublic

Authored by dereckson on Oct 21 2024, 00:19.
Tags
None
Referenced Files
F11077807: D3549.id9120.diff
Wed, Aug 13, 07:08
F11076865: D3549.id9118.diff
Wed, Aug 13, 05:05
F11071973: D3549.diff
Tue, Aug 12, 18:07
F11071051: D3549.id9119.diff
Tue, Aug 12, 16:04
Unknown Object (File)
Tue, Aug 12, 03:37
Unknown Object (File)
Sun, Aug 10, 19:47
Unknown Object (File)
Sun, Aug 10, 16:54
Unknown Object (File)
Sun, Aug 10, 05:39
Subscribers
None

Details

Summary

Brute-force attacks can create a lot of noise in system logs.
It could be convenient to be able to use a command to block a specific IP:

$ pfctl -t badhosts -T add $IP_TO_BLOCK

pf has the advantage to create easier to read rules than ipfilter and ipfw,
and to be still actively maintained.

Test Plan

Deployed on Hervil

Diff Detail

Repository
rOPS Nasqueron Operations
Lint
Lint Not Applicable
Unit
Tests Not Applicable