Truman BoyesZeros & Ones

archive · News

ipfw firewall and rate-limiting icmp

By Truman Boyes · · 2 min read

I was pleased that I was able to get the FreeBSD ipfw firewall to provide rate-limiting for ICMP and basically was able to apply a basic set of filtering rules for a server recently.

It's been a while since I spent much time doing any sort of system administration or real unix stuff. I tend to stay a way from that stuff these days, as it doesn't interest me like it used to. However, time and time, I do find some quirky setups or programs that are a good challenge to setup and learn.

I guess it pays off learning up on IPFW for the server, because it's also the same firewall included with OS X. (I am not sure if DUMMYNET kernel options are included in the OSX/Darwin generic kernels)...

If you are running FreeBSD, take a look at /etc/rc.firewall and take a peek at how it processes it's set of options. Basically it takes defines from /etc/rc.conf; some of these options are the type of firewall you are building. For example it could be a standalone box, a NAT router, or firewall protecting a whole subnet. In my case, I was just applying the firewall ruleset to an Internet server.

I ended up modifying /etc/rc.firewall to suite my needs, although most people probably just make their own ruleset files and pass those to ipfw. I opened up the necessary ports and then denying everything else.

Then I thought about ICMP, which was not specified anywhere in the templates. It would probably make sense to have some sort of policy regarding ICMP. I recognize the usefulness of ping, and although in the past I have been pretty strict with filtering of ping, I decided to rate-limit it instead of filter it.

After adding a snippet of rate-limiting rules like:

#Rate Limit ICMP
${fwcmd} pipe 1 config bw 5Kbit/s queue 5Kbytes
${fwcmd} add pipe 1 icmp from 1.1.1.1/32 to any frag
${fwcmd} add pipe 1 icmp from any to 1.1.1.1/32 frag

${fwcmd} pipe 2 config bw 10Kbit/s queue 10Kbytes
${fwcmd} add pipe 2 icmp from 1.1.1.1/32 to any
${fwcmd} add pipe 2 icmp from any to 1.1.1.1/32

I expected the system to now allow, but rate-limit ICMP. However ICMP didn't pass at all, but the statistics for each rule seemed to count up. I figured out that I was missing something pretty important when I recieved some serious error messages when I typed: ipfw pipe 1 show

My kernel didn't have the DUMMYNET options compiled in, so rate-limiting functions in ipfw are not valid. I jumped over to /usr/src/sys/i386/conf/; copied the GENERIC kernel over to the name of my server, and added the following lines to the kernel configuration:

options IPFIREWALL
options DUMMYNET
options HZ=1000

I then configured the kernel, built it, installed the new kernel and rebooted. Bingo!

/t/


Originally published on truman.net. See the archived copy.