Re: PF firewall for desktop

2019-05-28 Thread James Huddle
Lots of miscommunications in these threads. The original poster here was talking about setting up a virtual firewall machine to deal with traffic on a single box. Most of the war stories are from sys admins protecting a corporate LAN (or larger) with lawyers and accountants weighing in. Of

Re: PF firewall for desktop

2019-05-28 Thread Kevin Chadwick
On 5/24/19 8:30 PM, Jean-Francois Simon wrote: > Hi, > > Out of interest, I'd like to let you know a specific use of OpenBSD with PF, > in > virtualbox, 2 virtual network card Bridged to physical NIC, and building up a > subnet with NAT and hence running Packet Filter as the machine's firewall.

Re: PF firewall for desktop

2019-05-28 Thread Kapetanakis Giannis
On 28/05/2019 11:12, Janne Johansson wrote: > Den sön 26 maj 2019 kl 10:03 skrev Walt : > >> I like having a firewall that would pretty much require someone physically >> entering the computer room in order to attack the firewall. With OpenBSD, >> your firewall can control your network traffic

Re: PF firewall for desktop

2019-05-28 Thread Janne Johansson
Den sön 26 maj 2019 kl 10:03 skrev Walt : > I like having a firewall that would pretty much require someone physically > entering the computer room in order to attack the firewall. With OpenBSD, > your firewall can control your network traffic without having an IP address > at all. > One thing

Re: PF firewall for desktop

2019-05-27 Thread James Huddle
IP is a fairly high-order construct. Beneath it , the data link and physical layers remain almost unnoticed. One thought that came to mind would be to attack a machine on the same LAN, and then exploit an Ethernet vulnerability to listen to "the wire". Not sure how many (if any) Ethernet

Re: PF firewall for desktop

2019-05-26 Thread Walt
‐‐‐ Original Message ‐‐‐ On Friday, May 24, 2019 2:30 PM, Jean-Francois Simon wrote: > Hi, > > Out of interest, I'd like to let you know a specific use of OpenBSD with > PF, in virtualbox, 2 virtual network card Bridged to physical NIC, and > building up a subnet with NAT and hence

Re: PF firewall for desktop

2019-05-25 Thread James Huddle
I like your suggestion! I am security paranoid to a fault. For me, a system is either rock solid or wide open. obsd is the closest I've found to rock solid, and frankly a virtualbox vm running on win7 feels wide open. But the more I thought about your idea, the more I liked it. Win7 w/o the

PF firewall for desktop

2019-05-24 Thread Jean-Francois Simon
Hi, Out of interest, I'd like to let you know a specific use of OpenBSD with PF, in virtualbox, 2 virtual network card Bridged to physical NIC, and building up a subnet with NAT and hence running Packet Filter as the machine's firewall. That's the firewall I use under Win7, OpenBSD running