Re: Migration from IPTABLES to PF

2009-05-04 Thread William Chivers
This is a great advertisement for OpenBSD, PF, and keeping things simple in general, mind if I use it Ricardo? As for your original question, I wouldn't even try to convert your iptables, especially using some magic tool to do it. Decide what you want your firewall to do and start from scratch

Re: Migration from IPTABLES to PF

2009-05-04 Thread Giancarlo Razzolini
Mark Shroyer escreveu: On Mon, May 04, 2009 at 04:46:16PM -0300, Gonzalo Lionel Rodriguez wrote: jaja OMG... i love PF and OpenBSD. 2009/5/4 Jason Dixon : LOL, you ain't seen nothing yet. Look at the "extended version" he just sent out. :) To be fair, I've seen some pretty h

Re: Migration from IPTABLES to PF

2009-05-04 Thread Jason Dixon
On Mon, May 04, 2009 at 04:14:45PM -0400, Mark Shroyer wrote: > On Mon, May 04, 2009 at 04:46:16PM -0300, Gonzalo Lionel Rodriguez wrote: > > jaja OMG... i love PF and OpenBSD. > > > > 2009/5/4 Jason Dixon : > > > LOL, you ain't seen nothing yet. Look at the "extended version" he just > > > sent

Re: Migration from IPTABLES to PF

2009-05-04 Thread Gonzalo Lionel Rodriguez
Dont be fair ;) 2009/5/4 Mark Shroyer : > On Mon, May 04, 2009 at 04:46:16PM -0300, Gonzalo Lionel Rodriguez wrote: >> jaja OMG... i love PF and OpenBSD. >> >> 2009/5/4 Jason Dixon : >> > LOL, you ain't seen nothing yet. Look at the "extended version" he just >> > sent out. :) > > To be fair, I

Re: Migration from IPTABLES to PF

2009-05-04 Thread Mark Shroyer
On Mon, May 04, 2009 at 04:46:16PM -0300, Gonzalo Lionel Rodriguez wrote: > jaja OMG... i love PF and OpenBSD. > > 2009/5/4 Jason Dixon : > > LOL, you ain't seen nothing yet. Look at the "extended version" he just > > sent out. :) To be fair, I've seen some pretty horrid pf.conf files, too. (A

Re: Migration from IPTABLES to PF

2009-05-04 Thread Gonzalo Lionel Rodriguez
jaja OMG... i love PF and OpenBSD. 2009/5/4 Jason Dixon : > On Mon, May 04, 2009 at 04:34:55PM -0300, Gonzalo Lionel Rodriguez wrote: >> 2009/5/4 Marco Peereboom : >> > MY EYES!!! make it stop bleeding!!! >> >> jajajaja i think the same. grrr > > LOL, you ain't seen nothing yet. Look at the "exte

Re: Migration from IPTABLES to PF

2009-05-04 Thread Jason Dixon
On Mon, May 04, 2009 at 04:34:55PM -0300, Gonzalo Lionel Rodriguez wrote: > 2009/5/4 Marco Peereboom : > > MY EYES!!! make it stop bleeding!!! > > jajajaja i think the same. grrr LOL, you ain't seen nothing yet. Look at the "extended version" he just sent out. :) -- Jason Dixon DixonGroup Con

Re: Migration from IPTABLES to PF

2009-05-04 Thread Gonzalo Lionel Rodriguez
jajajaja i think the same. grrr 2009/5/4 Marco Peereboom : > MY EYES!!! make it stop bleeding!!! > > On Mon, May 04, 2009 at 02:17:33PM -0300, Ricardo Augusto de Souza wrote: >> Hi, >> >> I have a firewall running on a Fedora Core 4 (STentz) with iptables. The Guy >> Who installed it left our comp

Re: Migration from IPTABLES to PF

2009-05-04 Thread Kevin Wilcox
2009/5/4 Ricardo Augusto de Souza : > #___ > # Protecao do KERNEL > #___ > #Enable forwarding in kernel > echo 1 > /proc/sys/net/ipv4/ip_forward man sysc

Re: Migration from IPTABLES to PF

2009-05-04 Thread Mark Shroyer
On Mon, May 04, 2009 at 02:17:33PM -0300, Ricardo Augusto de Souza wrote: > Hi, > > I have a firewall running on a Fedora Core 4 (STentz) with iptables. The Guy > Who installed it left our company some months ago. > I spent some years far from iptables, now i have to migrate this firewall to > PF.

Re: Migration from IPTABLES to PF

2009-05-04 Thread Marco Peereboom
MY EYES!!! make it stop bleeding!!! On Mon, May 04, 2009 at 02:17:33PM -0300, Ricardo Augusto de Souza wrote: > Hi, > > I have a firewall running on a Fedora Core 4 (STentz) with iptables. The Guy > Who installed it left our company some months ago. > I spent some years far from iptables, now i h

Re: Migration from IPTABLES to PF

2009-05-04 Thread John Chronister
Ricardo, Why don't you try "Firewall Builder". http://www.fwbuilder.org/ It handles iptables, pf, and others. Should be able to import your iptables ruleset ( created by doing something like "/sbin/iptables-save > turdwall.txt" ) and then convert it to a pf.conf. You will still want to manuall

Re: Migration from IPTABLES to PF

2009-05-04 Thread Jason Dixon
On Mon, May 04, 2009 at 02:17:33PM -0300, Ricardo Augusto de Souza wrote: > Hi, > > I have a firewall running on a Fedora Core 4 (STentz) with iptables. The Guy > Who installed it left our company some months ago. > I spent some years far from iptables, now i have to migrate this firewall to > PF.