Defend your network and privacy : VPN gateway with OpenBSD

Discussion in 'privacy general' started by gkweb, May 11, 2014.

Thread Status:
Not open for further replies.
  1. gkweb

    gkweb Expert Firewall Tester

    Joined:
    Aug 29, 2003
    Posts:
    1,932
    Location:
    FRANCE, Rouen (76)
  2. mirimir

    mirimir Registered Member

    Joined:
    Oct 1, 2011
    Posts:
    9,252
    Very cool :thumb: Thanks :)

    This could also be a VM, by the way, similar to the pfSense VPN-client VMs that I go on about.

    As I understand pfSense, restricting an "allow from LAN" rule to a VPN gateway implements policy-based routing. Is that correct? I don't know the guts of pf well enough to do a rule-by-rule comparison with the pfSense setup that I'm using :( That's why I'm using pfSense. But I'd be happy to dump the rules if you were willing to look.
     
  3. gkweb

    gkweb Expert Firewall Tester

    Joined:
    Aug 29, 2003
    Posts:
    1,932
    Location:
    FRANCE, Rouen (76)
    Thanks for your comments :)

    Sadly I never tried pfSense, so I cannot really tell you how they do their filtering. Also, it's better to stay with something you understand and you are confortable with,
    rather than using someone else rules which may not fit to your network. Also as pfSense is based on FreeBSD, pf syntax may be different than OpenBSD.
    Anyway I'm pretty sure pfSense is doing it right, there is no need to worry about it :)

    Regards,
    Guillaume.
     
  4. Sabrina75

    Sabrina75 Registered Member

    Joined:
    Jun 5, 2014
    Posts:
    16
    Location:
    the middle of nowhere, exactly
    Congrats ! :thumb: et merci !
     
    Last edited: Jun 6, 2014
  5. gkweb

    gkweb Expert Firewall Tester

    Joined:
    Aug 29, 2003
    Posts:
    1,932
    Location:
    FRANCE, Rouen (76)
    You are welcome, always glad to help ;)
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.