gatekeeper.isi.deterlab.net
Gatekeeper is a bridging firewall running FreeBSD 7.3 and pf.
Hardware
- Dell PowerEdge Chassis
- Pentium 4 2.4Ghz
- 256Mb of RAM
- 40GB Seagate ST340014A Hard Drive
Interfaces
- Dual Port Card 1
- em0 internet facing interface (verify)
- em1 testbed facing interface (verify)
- Dual Port Card 2
- em2 is unused
- em3 10.0.23.0/24 network, address 10.0.23.254
Bridging Configuration
PF configuration
- The pf.conf file is in CVS under /operations/configuration/gatekeeper
- The kernel configuration in /operations/configuration/gatekeeper contains the pf and pflog devices:
device pf
device pflog
NAT Configuration
- We have a NAT'ed network hanging off of gatekeeper for machines that need to access the internet, but do not need to have it.
- The sysctl variable for ip forwarding is enabled in /etc/sysctl.conf:
net.inet.ip.forwarding=1