Commit graph

103 commits

Author SHA1 Message Date
Gabor Kovesdan
7ba98a21ad MFH
Approved by:	doceng (implicit)
2012-08-19 23:05:52 +00:00
Gabor Kovesdan
74586f38c6 - Remove PSGML comments since they are not very useful after the XML
migration

Approved by:		doceng (implicit)
No objection from:	doc@, www@
2012-08-07 23:31:39 +00:00
Isabell Long
5e30e0acb7 There is no need to compile IPFW into the FreeBSD kernel to make use of NAT
functionality anymore, so remove these sentences.

PR:		docs/144543
Approved by:	gjb (mentor)
2012-07-26 23:12:22 +00:00
Gabor Kovesdan
3cdf4e4922 - XMLify English books
Approved by:	doceng (implicit)
2012-06-21 16:04:40 +00:00
Eitan Adler
2bdc87af7b Fix a variety of duplicate and misspelled words
Approved by:	dougb
2012-03-17 04:53:52 +00:00
Eitan Adler
7d35fc35d6 Fix a variety of English style nits and other issues found with igor.
Reviewed by:	gabor
Approved by:	wblock
2012-02-13 23:21:10 +00:00
Glen Barber
4f02801ed7 Update or remove some broken link in the Handbook. 2012-01-16 02:33:46 +00:00
Glen Barber
bd8610e240 Document as of r223637, FreeBSD's PF version is in sync with OpenBSD 4.5. 2011-10-17 00:52:46 +00:00
Ryusuke SUZUKI
e7f9bd6ba7 Update the description of RULE_NUMBER.
PR: docs/150736
Reported by: brucec@
2011-04-14 14:35:46 +00:00
Rene Ladan
fffad858e3 Remove support for FreeBSD prior to 7.0 from the Handbook.
More specifically:
- mentions of old versions of FreeBSD in historical context are left in tact
- remove section about KerberosIV
- remove section about SAP R/3
- remove mentions of XFree86
- only support gvinum
- update examples to 7.X or 8.X
- remove Alpha support
- add COMPAT_FREEBSD[67] kernel options
- csup(1) now only in the base system
- update (tty) device names, add warnings for 7.X
- remove MD5 from the port checksum algorithms
- update port versions (probably not all)
- add definitions for ctm-src[5-8] to mailing-lists.ent

Reviewed by:	bcr, joel, remko, simon
2010-12-01 20:37:05 +00:00
Gabor Pali
1f5684243a - Reference ipf(5) instead of ipmon(8) because it is a better
source of information regarding logging TCP packets, and it already
  points to that manual page

PR:		docs/144881
Submitted by:	Glen Barber <glen.j.barber@gmail.com>
2010-08-10 12:20:24 +00:00
Gabor Pali
be75eda89c - Change security to local0 for ipmon(8) as the default syslogd(8) logging
facility, since this is how it works these days.

PR:		docs/131584
Submitted by:	Joe <joeb@a1poweruser.com>
2010-07-17 05:20:55 +00:00
Benedict Reuschling
b7cb958f9d Add the version of PF in FreeBSD 8.X to the handbook. The patch in the PR
was modified because handbook descriptions regarding FreeBSD 5.X and 6.X
are not mainstream anymore. Fix this by collapsing the list into a single
sentence.

Discussed with: jkois (mentor)
Approved by:    jkois (mentor)
PR:             docs/141042
Submitted by:   Glen Barber (glen dot j dot barber at gmail dot com)
2009-12-11 20:13:07 +00:00
Brad Davis
6a33ba5dde Clean up the PF section on loading kernel modules.
- Give specific clear examples on how to load the pf module and the pflog module.
- Remove some information that is stated in the section right above.
- Update the doc to reflect that pflog is now its own module. [1]

PR:		140896 [1]
2009-11-27 17:11:33 +00:00
Manolis Kiagias
ed49451c6a IPFW uses 'deny' (or 'drop') instead of 'block'.
Fix two examples and slightly rephrase the description for clarity.

Submitted by:	Nikos Isaris <nakaliptos at gmail dot com>
2009-09-01 13:41:42 +00:00
Ganbold Tsagaankhuu
3131085dc0 s/insure/ensure 2009-05-19 15:43:13 +00:00
Ganbold Tsagaankhuu
b1844d2f5f s/them/then 2009-05-19 15:27:01 +00:00
Manolis Kiagias
8022eecc1c A revamp of Handbook's 'firewalls' chapter.
This is a rather lengthy patch, that attempts to fix several problems:

- Reduce repetition. There are several paragraphs in the original text that are repeated throughout the sections
- Markup fixes. Replace single quotes with <literal> tags, add <acronym>s and several other changes to improve markup consistency
- Convert to passive voice where possible, eliminate few first person references
- Several grammar and language fixes
- The original text implied that the same TCP packet would go back and forth between source and destination.  Rephrase relevant paragraphs to clarify these are different packets
- Includes many fixes submitted in a PR [1] and a link fix submitted on -doc [2]
- Numerous other smaller changes, too many to mention here

PR:		docs/131568 [1]
Submitted by:	Chris Pepper <pepper@cbio.mskcc.org> [1]
Submitted by:	Phillip Nordwall <Phillip.Nordwall@wwu.edu> [2]
Reviewed by: 	trhodes, keramida
2009-05-13 17:20:58 +00:00
Daniel Gerzo
64579782ad - remove WIP note from the IPFW section, I don't think it belongs there,
all documentation is actually WIP...

- add a note that IPFW now supports both IPv4 and IPv6

- remove now obsoleted IPV6FIREWALL* options (see
  http://lists.freebsd.org/pipermail/freebsd-questions/2008-December/189329.html)

Inspired by:	http://forums.freebsd.org/showthread.php?t=1110
2008-12-24 01:33:40 +00:00
Gabor Pali
edafad6a69 Eliminate erroneous role="directory" attributes from <filename> elements
and replace them with class="directory" [1][2]

[1] http://docbook.org/tdg/en/html/filename.html
[2] http://www.freebsd.org/doc/en/books/fdp-primer/sgml-markup-docbook.html#AEN1799
    (4.2.5.5)

Approved by:	trhodes, gabor (mentor)
2008-08-06 22:03:50 +00:00
Daniel Gerzo
469b984976 - remove superfluous character. 2008-07-17 18:16:19 +00:00
Gabor Kovesdan
2950a3e2b8 - Reword and reorganize the PF subchapter to be clearer and easier to
use. Mention the changed location of a configuration file in 7.0.

PR:		docs/122351, docs/121321 (related)
Submitted by:	John Ferrell <jdferrell3@yahoo.com>
2008-06-15 13:16:49 +00:00
Remko Lodder
52425992c2 Borrow Poul-Henning's Axe and chop out old information for 4.x, 5.x
and unsupported 6.x releases. Tom started this process a while ago
and I'll follow up on that for the latest EoL round.

The old versions can still be found in the doc archives:
http://docs.freebsd.org/doc/
2008-06-01 09:42:12 +00:00
Fukang Chen
d3d9272c52 s/option divert/option IPDIVERT/ to enable support for divert sockets.
Obtained from:          The FreeBSD Simplified Chinese Project
Submitted by:           zheng chengfu (iheaing at gmail.com)
2008-03-01 17:50:03 +00:00
Remko Lodder
ac6bf8b645 s/IPF/PF/ (with acronym tags around it as was the case before modifying
the text).

Noticed by:	danger
2008-01-17 17:50:30 +00:00
Remko Lodder
8733db6ed1 IPF does not have ALTQ support (or at least not that I and several others
could find) so remove it from the information, give an example on how
such a setup can be achieved.

PR:		docs/113464
Submitted by:	Josh Paetzel <josh at tcbug dot org>
Inspired by:	Marc Silver <marcs at draenor dot org> (slightly rewritten
		by me).
2008-01-17 13:38:31 +00:00
Remko Lodder
8480a57a44 s/examble/example/ 2007-12-28 20:17:18 +00:00
Tom Rhodes
89c2fddcd7 Add a space to separate two words. 2007-10-06 00:04:22 +00:00
Remko Lodder
babc93b92a Remove a section about ipfilter FTP Proxy Bugs, which were resolved in
version 3.4.3 released in 2000, a little ago.

PR:		docs/95263
Submitted by:	Joe <fbsd_user at a1poweruser dot com>
2007-07-02 19:46:27 +00:00
Peter Pentchev
ac0dc22ace Fix an address specification in the IPNAT port redirection example.
Left as 0/32, it would only redirect Very Weird Packets(tm), while
as 0.0.0.0/0 it will indeed process all the traffic as intended.

Submitted by:	"Michael P. Soulier" <msoulier@digitaltorque.ca>
2007-04-25 15:01:58 +00:00
Xin LI
af80ec8c86 Remove an unnecessary sentence. 2006-11-17 14:37:11 +00:00
Tom Rhodes
f0a1a631d6 Replace some confusing text about "IPFW being loaded/not being loaded/blah"
with some more relevent and clear text about using rc.conf to load the
firewall.

PR		99336
Discussed with:	keramida (follow up to PR, etc.)
2006-10-10 02:56:06 +00:00
Daniel Gerzo
da68e1b2ca Add some bits about firewall_script and firewall_type rc.conf
variables to ipfw section.

Reviewed by: trhodes
Approved by: keramida (mentor)
PR: docs/93764
2006-08-26 00:13:26 +00:00
Giorgos Keramidas
74dc593238 ipnat doesn't support IP ranges with a.b.c.d-w.x.y.z notation,
but only with /netmask or /cidr notation

PR:		docs/95261
Submitted by:	fbsd_user@a1poweruser.com
2006-08-08 20:22:08 +00:00
Dmitry Morozovsky
1f21c1cd4c Clean a couple of 4.X references. 2006-06-20 10:55:38 +00:00
Tom Rhodes
e665ef072f Document "firewall_type" in this chapter.
PR:	38772
2006-06-07 05:34:30 +00:00
Tom Rhodes
3f0d1b56f0 Do what I swore would be done:
o Remove 4.X information, this includes notes and sections.

o Update documentation to reflect 5.X and 6.X.

o In some areas, try to make the new content version agnostic.

o Skip areas stating "5.[0-5] and later" as it's relevant - we
need a better way to handle these.

For several items, I checked the NOTES files, manual pages,
CVS history, etc.

Discussed on:		-doc
A few ideas from:	remko
2006-05-30 23:08:25 +00:00
Giorgos Keramidas
97253f8b53 Point to the searchable archives of the opensource IPFilter mailing list,
at marc.aimsgroup.com.

PR:		docs/95264
Submitted by:	fbsd_user@a1poweruser.com
2006-05-10 18:44:04 +00:00
Jesus R. Camou
8b6b3736bb Note the use of NOINET6 on the FreeBSD 5.X series.
Submitted by:	Daniel Gerzo <danger at rulez.sk>
Approved by:	trhodes (mentor)
2006-02-07 17:00:51 +00:00
Jesus R. Camou
5ec730e921 s/NOINET6/NO_INET6/
PR:		docs/92816
Submitted by:	Daniel Gerzo <danger@rulez.sk>
Approved by:	trhodes (mentor)
2006-02-06 19:13:19 +00:00
Brad Davis
e4de67ee62 - Restructure part of the PF section.
- Add general info about enabling PF and creating rulsets.

PR:		docs/92113
Submitted by:	Daniel Gerzo <danger at rulez dot sk>
Reviewed by:	simon@ and ceri@
Approved by:	ceri@
2006-01-22 22:20:42 +00:00
Xin LI
e140896ec8 Escape <, >, &'s, plus some cleanups against the SGML. There should not
be any content changes involved in this commit, however, localization
teams are encouraged to catch up with this change.

Requested by:	intron at intron ac
Reviewed by:	Niclas Zeising <lothrandil at n00b apagnu se>
Glanced by:	simon
2006-01-05 20:03:39 +00:00
Marc Fonvieille
d9e3f806ca In IPFW section: point people to network-natd section when it's time to
configure the system via rc.conf.  This avoids to repeat things and
allows the reader to complete the natd(8) configuration.

Based on PR:		docs/81199
Submitted by:		Rong-En Fan <rafan@infor.org>
2005-05-19 09:13:32 +00:00
Marc Fonvieille
b0f21913af Typo
PR:		docs/81242
Submitted by:	David Adam <zanchey@ucc.gu.uwa.edu.au>
2005-05-19 08:42:49 +00:00
Remko Lodder
ee8497f48c Add forgotten spaces and add 2 non breaking spaces for &os; 5.X and 4.X.
Noticed by:		blackend
Forgotten by:		remko (me)
2005-05-08 14:15:43 +00:00
Remko Lodder
280011b864 Update the IPMON section by making it suitable for 5.X (and reference
4.X for people still using 4.X).

PR:			docs/79543
Submitted by:		<fbsd_user at a1poweruser dot com>
2005-05-08 12:45:29 +00:00
Remko Lodder
76a6af4884 Let portredirection be rdr instead of map (which is NAT).
Noticed by:		Andrius Paurys <shaman at shaman dot velniai dot net>
2005-05-01 20:44:49 +00:00
Simon L. B. Nielsen
bac2a185c2 - Reword some text.
- Use firewall package instead of firewall software application.
- Do not say non-stateful firewall's are "legacy" since they still
  make sense in some cases.
- Move paragraph about /etc/rc.firewall to the ipfw section and don't
  say it's outdates, just simple. [1]

Inspired by:	den [1]
2005-03-31 21:11:56 +00:00
Simon L. B. Nielsen
9dfb6473b5 Add a note about the IPF and IPFW sections being work-in-progress. This
is far from a good situation, but it's better to be up front about it.

Discussed with:	den, remko
2005-03-31 19:38:18 +00:00
Max Laier
9e9bc62ee3 Add notes about required kernel options for PF as a module and explain how
to build an IPv6-less setup.

Approved by:	simon
Inspired by PR:	kern/70401
2005-03-16 12:57:30 +00:00