Re: openbsd firewall configuration for extreme hostile environment

2023-05-07 Thread jonathon575
Thank you very much Nick. I truly appreciate your advise. Jonathon. Sent with Proton Mail secure email. --- Original Message --- On Tuesday, May 2nd, 2023 at 2:01 AM, Nick Holland wrote: > On 4/26/23 08:46, jonathon575 wrote: > > > Greetings, > > > > I have OpenBSD configured stri

Re: openbsd firewall configuration for extreme hostile environment

2023-05-02 Thread Stuart Henderson
On 2023-04-26, jonathon575 wrote: > The services in the file rc.conf are kept in its default state which is > mostly disabled. the binary files sshd, portmap, ntpd are deleted from the > /bin directory. Other binary files telnet, ssh, scp, sftp are removed to > prevent any file transfer from th

Re: openbsd firewall configuration for extreme hostile environment

2023-05-02 Thread Stuart Henderson
On 2023-04-26, jonathon575 wrote: >>> #What firewall was compromised - your OpenBSD based firewall? ... hope you >>> did a fresh >>> install from scratch on this device... >>> >>> Yes, it was OpenBSD based firewall 7.1. Fresh install from scratch didn't >>> help as the attack appeared again. In

Re: openbsd firewall configuration for extreme hostile environment

2023-05-01 Thread Nick Holland
On 4/26/23 08:46, jonathon575 wrote: Greetings, I have OpenBSD configured strictly as a dedicated firewall. Only BSD, BSD.rd, BSD.mp, and Base are installed (supposedly, this is the minimum installation). Blocked All, and only few selected out going IP addresses are allowed (strictly vpn ip addr

Re: openbsd firewall configuration for extreme hostile environment

2023-04-26 Thread jonathon575
Greetings, I have OpenBSD configured strictly as a dedicated firewall. Only BSD, BSD.rd, BSD.mp, and Base are installed (supposedly, this is the minimum installation). Blocked All, and only few selected out going IP addresses are allowed (strictly vpn ip addresses). I maintained rc.conf at its

Re: openbsd firewall configuration for extreme hostile environment

2023-04-26 Thread jonathon575
Greetings, I have OpenBSD configured strictly as a dedicated firewall. Only BSD, BSD.rd, BSD.mp, and Base are installed (supposedly, this is the minimum installation). Blocked All, and only few selected out going IP addresses are allowed (strictly vpn ip addresses). I maintained rc.conf at its