I just wrapped up an interesting call that was originally scheduled for last week but rescheduled for today. The client is looking for a unique setup, and thanks to having an early re-read of the fantastic The Book of PF - 4th Edition, I was able to propose some configurations that had completely slipped my mind. The client is extremely curious, and this will likely lead to a new OpenBSD deployment in an interesting environment.

At the same time, I received an email from a professor at an Italian university whom I had encouraged to extend his lectures to include BSDs. I piqued his curiosity as well and proposed a session specifically on firewalls, focusing on OpenBSD and pf. He will be reading The Book of PF soon and will likely add it to his students' recommended reading list. I'll probably present them, too.

In short - one book, a thousand new possibilities. Infinite thanks to @pitrh for the massive and wonderful work behind it.

https://nostarch.com/book-of-pf-4th-edition

#OpenBSD #FreeBSD #NetBSD #RunBSD #PF #Firewalling #IT #SysAdmin

The Book of PF, 4th Edition

Build a more secure network with PF.

Is there a set of IPs/ASNs from which #letsencrypt is performing the HTTP-01 challenge? #networking #firewalling

Buenos días #fediverso!! Tengan excelente miércoles!! 👋

Yo aquí sigo, tomando unos mates 🧉 y redondeando un artículo sobre el flujo de trabajo de un firewall #xtables en #Linux, y preparando contenido del nuevo curso de #nftables de #juncotic, que ya queda poquito!!

   #gnu #linux #firewall #iptables #networking #infosec #cybersecurity #firewalling #tcpip

Cerrando la semana con las grabaciones del nuevo curso de #firewalling con #nftables en #linux!

Se viene también nuevo contenido para el curso de #iptables :)

¿Les interesa que considere añadir algún tema puntual?

¡Dejamelo en los comentarios!
Buen fin de semana!

Fresh out of the Oven.

I was searching for the best replacement of my Lenovo X1 Carbon 8th Gen's Wirreless Card (...not found yet - anyone?), and found this instead, which may be my 2morrows read:

A #beginners Guide To #Firewalling with #pf #pfsense

https://srobb.net/pf.html

Maybe also interesting site for @vermaden s BSD-News? §8-)

A Beginner's Guide to Firewalling with pf

Seguimos preparando contenido para el nuevo curso de #firewalling con #nftables de juncotic.com :D

La semana que viene empezamos con las grabaciones! 💪

IMPORTANT QUESTION: would you be affected if parltrack started #firewalling #aws, #azure and #cloudflare?

¿Te interesa #linux #flask #python #redes #tcpip #wireshark #ssh #iptables #firewalling #vim o #bash ?

Acá te dejo un 🧵 donde van a poder encontrar cupones de descuento para todos los cursos de @juncotic

Me escriben por otras formas de pago, y no se dejen estar, quedan 2 días!

https://mstdn.io/@d1cor/113783865137910918

Diego Cordoba 🇦🇷 (@[email protected])

Todos los cursos de JuncoTIC.com en promoción por 5 días más! Para empezar el año aprendiendo cosas nuevas :P Me escriben por otros medios de pago (transferencia, MP, airtm, paypal, payoneer, binance). Los espero! 🔥 [NUEVO] Construye aplicaciones web dinámicas con Flask Aprende paso a paso a construir aplicaciones web dinámicas y adaptadas a diferentes necesidades usando Python https://www.udemy.com/course/aplicaciones-web-dinamicas-con-flask/?couponCode=JUNCOTIC_2501MIN (sigue)

Mastodon

@ariadne That could be integrated however, and the blocklist linked is for entire domains, so #Firewalling works...

But yeah I think these should be integrated and I'm convinced admins like @stux would prefer a smooth "setup & forget" option similar to #pfBlockerNG being integrated natively in #ActivityPub server software...

Cuz that works very well in almost all cases:
https://docs.netgate.com/pfsense/en/latest/packages/pfblocker.html

Packages — pfBlocker-NG Package | pfSense Documentation

@yakkoj Have you ever considered using #Netplan?

#ItJust works and also does all the nice stuff, like #VLAN's and #Bonding...

https://netplan.io/

Personally, I prefer putting #firewalling into the #Networking segment and put a #pfSense, #tnsr or #OPNsense in between it and the Interwebz.

But Netplan allows you to go precise and i.e. specify that no incoming connections are permitted on the Storage-LAN used for iSCSI traffic at MTU 9k and other stuff...

Netplan | Canonical Netplan

Backend-agnostic network configuration in YAML.