Chapter 22. Advanced PF

Office net seems slow
thanks to bootleg film swapping.
Let’s stop that right quick!

The previous chapter covered the basics of the OpenBSD packet filter pf(4). But, as I mentioned, PF can manipulate packets in all kinds of ways beyond just permitting or denying them, including the following:

  • You can dynamically change the list of addresses to pass or block through outside software, such as dhcpd(8) or spamd(8).

  • You can dynamically create sub-rulesets that let you set up very specific rules for troublesome protocols without allowing more access than necessary.

  • PF can provide NAT, letting you offer an entire network Internet access without public IP addresses.

  • You can redirect incoming traffic arbitrarily, and control how much bandwidth you will let a service use.

  • You can use PF logging.

This chapter covers each of these topics.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.143.235.23