SlideShare a Scribd company logo
1 of 1
Download to read offline
PF on OpenBSD Filtering Rules Diagram
pass in on egress TCP from any to 192.0.2.12 port 80
What to do if
rule matches;
Results of
matching the
rule
(pass/block/m
atch)
Direction
the
packets
are going;
towards
the
computer
or away
from the
computer
(in/out)
Interface
group or
interface;
To match
every
interface,
use “all”
Type of
protocol
connection
(TCP/UDP/
ICMP/ICM
P6)
Where is
traffic
coming
from ie: IP
address or
can use
hostnames
What
specific IP
address is
the
connection
being
made to on
local
machine or
“any”; can
use
hostnames
What port
does it
connect to
on a local
machine
Adopted from “Absolute OpenBSD”, p 403-409

More Related Content

What's hot

Relay and AVR Atmel Atmega 16
Relay and AVR Atmel Atmega 16Relay and AVR Atmel Atmega 16
Relay and AVR Atmel Atmega 16Robo India
 
Microcontrollers iii
Microcontrollers iiiMicrocontrollers iii
Microcontrollers iiiTeame Hadush
 
AVR programming - BASICS
AVR programming - BASICSAVR programming - BASICS
AVR programming - BASICSRobotix 2011
 
Input Output programming in AVR microcontroller
Input  Output  programming in AVR microcontrollerInput  Output  programming in AVR microcontroller
Input Output programming in AVR microcontrollerRobo India
 
Cisco Switch Security
Cisco Switch SecurityCisco Switch Security
Cisco Switch Securitydkaya
 
Detecting Reconnaissance Through Packet Forensics by Shashank Nigam
Detecting Reconnaissance Through Packet Forensics by Shashank NigamDetecting Reconnaissance Through Packet Forensics by Shashank Nigam
Detecting Reconnaissance Through Packet Forensics by Shashank NigamOWASP Delhi
 

What's hot (8)

Relay and AVR Atmel Atmega 16
Relay and AVR Atmel Atmega 16Relay and AVR Atmel Atmega 16
Relay and AVR Atmel Atmega 16
 
Microcontrollers iii
Microcontrollers iiiMicrocontrollers iii
Microcontrollers iii
 
AVR programming - BASICS
AVR programming - BASICSAVR programming - BASICS
AVR programming - BASICS
 
Input Output programming in AVR microcontroller
Input  Output  programming in AVR microcontrollerInput  Output  programming in AVR microcontroller
Input Output programming in AVR microcontroller
 
Modscan r0x
Modscan r0xModscan r0x
Modscan r0x
 
Cisco Switch Security
Cisco Switch SecurityCisco Switch Security
Cisco Switch Security
 
Arp
ArpArp
Arp
 
Detecting Reconnaissance Through Packet Forensics by Shashank Nigam
Detecting Reconnaissance Through Packet Forensics by Shashank NigamDetecting Reconnaissance Through Packet Forensics by Shashank Nigam
Detecting Reconnaissance Through Packet Forensics by Shashank Nigam
 

Viewers also liked

Customer Experience Management by Buljan and Partners Consulting
Customer Experience Management by Buljan and Partners ConsultingCustomer Experience Management by Buljan and Partners Consulting
Customer Experience Management by Buljan and Partners ConsultingBuljan & Partners Consulting
 
文系フリーランス 新規事業ディスカッションパートナー(NBDP) 黒田悠介の自己紹介・価格表・実績
文系フリーランス 新規事業ディスカッションパートナー(NBDP) 黒田悠介の自己紹介・価格表・実績文系フリーランス 新規事業ディスカッションパートナー(NBDP) 黒田悠介の自己紹介・価格表・実績
文系フリーランス 新規事業ディスカッションパートナー(NBDP) 黒田悠介の自己紹介・価格表・実績Yusuke Kuroda
 
LinkedIn Recruiter
LinkedIn RecruiterLinkedIn Recruiter
LinkedIn Recruitersmcgettigan
 
NonProfit Social Media Ambassador Case Study
NonProfit Social Media Ambassador Case StudyNonProfit Social Media Ambassador Case Study
NonProfit Social Media Ambassador Case StudyJacquelyne Marianno
 
Excellence in Contact Centre & Customer Interaction Summit Barcelona 2014
Excellence in Contact Centre & Customer Interaction Summit Barcelona 2014Excellence in Contact Centre & Customer Interaction Summit Barcelona 2014
Excellence in Contact Centre & Customer Interaction Summit Barcelona 2014Karen Radley
 
Mi Plan de Desarrollo Personal
Mi Plan de Desarrollo PersonalMi Plan de Desarrollo Personal
Mi Plan de Desarrollo Personaljackellynem
 
Políticas de competencia en la era digital Guido Carrión
Políticas de competencia en la era digital Guido CarriónPolíticas de competencia en la era digital Guido Carrión
Políticas de competencia en la era digital Guido CarriónGuido Carrion
 
70553 35714 5242 65699 87912 9rosas
70553 35714 5242 65699 87912 9rosas70553 35714 5242 65699 87912 9rosas
70553 35714 5242 65699 87912 9rosasCARLOS CAVALLINI
 
Gana dinero con youtube
Gana dinero con youtubeGana dinero con youtube
Gana dinero con youtubeJo Moreno
 
TelephoneInfo-OpenInteraction
TelephoneInfo-OpenInteractionTelephoneInfo-OpenInteraction
TelephoneInfo-OpenInteractionMatt R
 
成功するフリーランスの自己理解
成功するフリーランスの自己理解成功するフリーランスの自己理解
成功するフリーランスの自己理解Yusuke Kuroda
 
Your employees as your brand ambassadors
Your employees as your brand ambassadorsYour employees as your brand ambassadors
Your employees as your brand ambassadorsPetra Neiger
 

Viewers also liked (16)

Tipos de conexion
Tipos de conexionTipos de conexion
Tipos de conexion
 
Customer Experience Management by Buljan and Partners Consulting
Customer Experience Management by Buljan and Partners ConsultingCustomer Experience Management by Buljan and Partners Consulting
Customer Experience Management by Buljan and Partners Consulting
 
文系フリーランス 新規事業ディスカッションパートナー(NBDP) 黒田悠介の自己紹介・価格表・実績
文系フリーランス 新規事業ディスカッションパートナー(NBDP) 黒田悠介の自己紹介・価格表・実績文系フリーランス 新規事業ディスカッションパートナー(NBDP) 黒田悠介の自己紹介・価格表・実績
文系フリーランス 新規事業ディスカッションパートナー(NBDP) 黒田悠介の自己紹介・価格表・実績
 
LinkedIn Recruiter
LinkedIn RecruiterLinkedIn Recruiter
LinkedIn Recruiter
 
Resume 1.1Ag
Resume 1.1AgResume 1.1Ag
Resume 1.1Ag
 
NonProfit Social Media Ambassador Case Study
NonProfit Social Media Ambassador Case StudyNonProfit Social Media Ambassador Case Study
NonProfit Social Media Ambassador Case Study
 
Excellence in Contact Centre & Customer Interaction Summit Barcelona 2014
Excellence in Contact Centre & Customer Interaction Summit Barcelona 2014Excellence in Contact Centre & Customer Interaction Summit Barcelona 2014
Excellence in Contact Centre & Customer Interaction Summit Barcelona 2014
 
Az
AzAz
Az
 
Mi Plan de Desarrollo Personal
Mi Plan de Desarrollo PersonalMi Plan de Desarrollo Personal
Mi Plan de Desarrollo Personal
 
Políticas de competencia en la era digital Guido Carrión
Políticas de competencia en la era digital Guido CarriónPolíticas de competencia en la era digital Guido Carrión
Políticas de competencia en la era digital Guido Carrión
 
70553 35714 5242 65699 87912 9rosas
70553 35714 5242 65699 87912 9rosas70553 35714 5242 65699 87912 9rosas
70553 35714 5242 65699 87912 9rosas
 
Gana dinero con youtube
Gana dinero con youtubeGana dinero con youtube
Gana dinero con youtube
 
TelephoneInfo-OpenInteraction
TelephoneInfo-OpenInteractionTelephoneInfo-OpenInteraction
TelephoneInfo-OpenInteraction
 
成功するフリーランスの自己理解
成功するフリーランスの自己理解成功するフリーランスの自己理解
成功するフリーランスの自己理解
 
Your employees as your brand ambassadors
Your employees as your brand ambassadorsYour employees as your brand ambassadors
Your employees as your brand ambassadors
 
Dossier Buljan and Partners Consulting
Dossier Buljan and Partners ConsultingDossier Buljan and Partners Consulting
Dossier Buljan and Partners Consulting
 

More from Matt R

EstimateExtraterrestrialLife
EstimateExtraterrestrialLifeEstimateExtraterrestrialLife
EstimateExtraterrestrialLifeMatt R
 
LinuxPresentation500kb
LinuxPresentation500kbLinuxPresentation500kb
LinuxPresentation500kbMatt R
 
PythonShutdownWindows
PythonShutdownWindowsPythonShutdownWindows
PythonShutdownWindowsMatt R
 
PhoneCallTools
PhoneCallToolsPhoneCallTools
PhoneCallToolsMatt R
 
LaptopTrustIssues
LaptopTrustIssuesLaptopTrustIssues
LaptopTrustIssuesMatt R
 
Interactions
InteractionsInteractions
InteractionsMatt R
 
Interaction-Incident
Interaction-IncidentInteraction-Incident
Interaction-IncidentMatt R
 
FoundationProcess
FoundationProcessFoundationProcess
FoundationProcessMatt R
 
FindStaffPerson
FindStaffPersonFindStaffPerson
FindStaffPersonMatt R
 
ChangesChecklist
ChangesChecklistChangesChecklist
ChangesChecklistMatt R
 
bigalsnetwork
bigalsnetworkbigalsnetwork
bigalsnetworkMatt R
 
DateDiffQuery
DateDiffQueryDateDiffQuery
DateDiffQueryMatt R
 
DualScreenDualCPU
DualScreenDualCPUDualScreenDualCPU
DualScreenDualCPUMatt R
 
LoyalKasparBackupPlanProposal
LoyalKasparBackupPlanProposalLoyalKasparBackupPlanProposal
LoyalKasparBackupPlanProposalMatt R
 
MattSampleDatabase
MattSampleDatabaseMattSampleDatabase
MattSampleDatabaseMatt R
 
PythonPythagoreanTheorem
PythonPythagoreanTheoremPythonPythagoreanTheorem
PythonPythagoreanTheoremMatt R
 
Sample Website
Sample WebsiteSample Website
Sample WebsiteMatt R
 
XenAppDoc
XenAppDocXenAppDoc
XenAppDocMatt R
 
SpecNetworkMap
SpecNetworkMapSpecNetworkMap
SpecNetworkMapMatt R
 

More from Matt R (20)

EstimateExtraterrestrialLife
EstimateExtraterrestrialLifeEstimateExtraterrestrialLife
EstimateExtraterrestrialLife
 
LinuxPresentation500kb
LinuxPresentation500kbLinuxPresentation500kb
LinuxPresentation500kb
 
PythonShutdownWindows
PythonShutdownWindowsPythonShutdownWindows
PythonShutdownWindows
 
PhoneCallTools
PhoneCallToolsPhoneCallTools
PhoneCallTools
 
LaptopTrustIssues
LaptopTrustIssuesLaptopTrustIssues
LaptopTrustIssues
 
Interactions
InteractionsInteractions
Interactions
 
Interaction-Incident
Interaction-IncidentInteraction-Incident
Interaction-Incident
 
FoundationProcess
FoundationProcessFoundationProcess
FoundationProcess
 
FindStaffPerson
FindStaffPersonFindStaffPerson
FindStaffPerson
 
ChangesChecklist
ChangesChecklistChangesChecklist
ChangesChecklist
 
3tabs
3tabs3tabs
3tabs
 
bigalsnetwork
bigalsnetworkbigalsnetwork
bigalsnetwork
 
DateDiffQuery
DateDiffQueryDateDiffQuery
DateDiffQuery
 
DualScreenDualCPU
DualScreenDualCPUDualScreenDualCPU
DualScreenDualCPU
 
LoyalKasparBackupPlanProposal
LoyalKasparBackupPlanProposalLoyalKasparBackupPlanProposal
LoyalKasparBackupPlanProposal
 
MattSampleDatabase
MattSampleDatabaseMattSampleDatabase
MattSampleDatabase
 
PythonPythagoreanTheorem
PythonPythagoreanTheoremPythonPythagoreanTheorem
PythonPythagoreanTheorem
 
Sample Website
Sample WebsiteSample Website
Sample Website
 
XenAppDoc
XenAppDocXenAppDoc
XenAppDoc
 
SpecNetworkMap
SpecNetworkMapSpecNetworkMap
SpecNetworkMap
 

OpenBSD-pf-filter

  • 1. PF on OpenBSD Filtering Rules Diagram pass in on egress TCP from any to 192.0.2.12 port 80 What to do if rule matches; Results of matching the rule (pass/block/m atch) Direction the packets are going; towards the computer or away from the computer (in/out) Interface group or interface; To match every interface, use “all” Type of protocol connection (TCP/UDP/ ICMP/ICM P6) Where is traffic coming from ie: IP address or can use hostnames What specific IP address is the connection being made to on local machine or “any”; can use hostnames What port does it connect to on a local machine Adopted from “Absolute OpenBSD”, p 403-409