Book description
OpenBSD's stateful packet filter, PF, offers an amazing feature set and support across the major BSD platforms. Like most firewall software though, unlocking PF's full potential takes a good teacher. Peter N.M. Hansteen's PF website and conference tutorials have helped thousands of users build the networks they need using PF. The Book of PF is the product of Hansteen's knowledge and experience, teaching good practices as well as bare facts and software options. Throughout the book, Hansteen emphasizes the importance of staying in control by having a written network specification, using macros to make rule sets more readable, and performing rigid testing when loading in new rules.
Today's system administrators face increasing challenges in the quest for network quality, and The Book of PF can help by demystifying the tools of modern *BSD network defense. But, perhaps more importantly, because we know you like to tinker, The Book of PF tackles a broad range of topics that will stimulate your mind and pad your resume, including how to:
Create rule sets for all kinds of network traffic, whether it is crossing a simple home LAN, hiding behind NAT, traversing DMZs, or spanning bridges
Use PF to create a wireless access point, and lock it down tight with authpf and special access restrictions
Maximize availability by using redirection rules for load balancing and CARP for failover
Use tables for proactive defense against would-be attackers and spammers
Set up queues and traffic shaping with ALTQ, so your network stays responsive
Master your logs with monitoring and visualization, because you can never be too paranoid
The Book of PF is written for BSD enthusiasts and network admins at any level of expertise. With more and more services placing high demands on bandwidth and increasing hostility coming from the Internet at-large, you can never be too skilled with PF.
Table of contents
-
The Book of PF
- THE BOOK OF PF
- FOREWORD
- PREFACE
- 1. WHAT PF IS
- 2. LET'S GET ON WITH IT
- 3. INTO THE REAL WORLD
- 4. WIRELESS NETWORKS MADE EASY
-
5. BIGGER OR TRICKIER NETWORKS
- When Others Need Something in Your Network: Filtering Services
- Back to the Single NATed Network
- The Power of Tags
- The Bridging Firewall
- Handling Nonroutable Addresses from Elsewhere
- 6. TURNING THE TABLES FOR PROACTIVE DEFENSE
-
7. QUEUES, SHAPING, AND REDUNDANCY
- Directing Traffic with ALTQ
- Redundancy and Failover: CARP and pfsync
- 8. LOGGING, MONITORING, AND STATISTICS
- 9. GETTING YOUR SETUP JUST RIGHT
- A. RESOURCES
- B. A NOTE ON HARDWARE SUPPORT
- About the Author
- COLOPHON
Product information
- Title: The Book of PF
- Author(s):
- Release date: December 2007
- Publisher(s): No Starch Press
- ISBN: 9781593271657
You might also like
book
The Book of PF, 2nd Edition
This second edition of The Book of PF is an up-to-date, no-nonsense guide to harnessing the …
book
The Book of PF, 3rd Edition
The Book of PF is the essential guide to building a secure network with PF, the …
article
Reinventing the Organization for GenAI and LLMs
Previous technology breakthroughs did not upend organizational structure, but generative AI and LLMs will. We now …
audiobook
The Year in Tech, 2025
<B>A year of HBR's essential thinking on tech—all in one place.</B><br/><br/><br/><br/>Generative AI, biometrics, spatial computing, electric …