BUY THIS BOOK
Add to Cart

Print Book $29.95

Safari Books Online

What is this?

The Book of PF A No-Nonsense Guide to the OpenBSD Firewall

By Peter N.M. Hansteen
December 2007
Publisher: No Starch Press
Pages: 184
ISBN 10: 1-59327-165-4 | ISBN 13: 9781593271657
starstarstarstarstar (Average of 1 Customer Reviews)

Buy 2 Get 1 Free Free ShippingGuarantee

Book description

A solid understanding of OpenBSD's PF subsystem is a necessity for any network administrator working in a *BSD environment. The Book of PF is a current, no-nonsense guidebook to harnessing the power of PF. Its contents include coverage of NAT (network address translation), wireless networking, spam fighting, traffic shaping, failover provisioning, and logging. Written for anyone who has felt lost in PF's manual pages or baffled by its massive feature set, author Peter Hansteen helps readers confidently build the high-performance, low maintenance network they need.
Full Description

OpenBSD's stateful packet filter, PF, offers an amazing feature set and support across the major BSD platforms. Like most firewall software though, unlocking PF's full potential takes a good teacher. Peter N.M. Hansteen's PF website and conference tutorials have helped thousands of users build the networks they need using PF. The Book of PF is the product of Hansteen's knowledge and experience, teaching good practices as well as bare facts and software options. Throughout the book, Hansteen emphasizes the importance of staying in control by having a written network specification, using macros to make rule sets more readable, and performing rigid testing when loading in new rules.

Today's system administrators face increasing challenges in the quest for network quality, and The Book of PF can help by demystifying the tools of modern *BSD network defense. But, perhaps more importantly, because we know you like to tinker, The Book of PF tackles a broad range of topics that will stimulate your mind and pad your resume, including how to:

  • Create rule sets for all kinds of network traffic, whether it is crossing a simple home LAN, hiding behind NAT, traversing DMZs, or spanning bridges
  • Use PF to create a wireless access point, and lock it down tight with authpf and special access restrictions
  • Maximize availability by using redirection rules for load balancing and CARP for failover
  • Use tables for proactive defense against would-be attackers and spammers
  • Set up queues and traffic shaping with ALTQ, so your network stays responsive
  • Master your logs with monitoring and visualization, because you can never be too paranoid

The Book of PF is written for BSD enthusiasts and network admins at any level of expertise. With more and more services placing high demands on bandwidth and increasing hostility coming from the Internet at-large, you can never be too skilled with PF.

Browse within this book

Cover




Featured customer reviews

Write a Review


Peter N.M. Hansteen photo Re: PF review by Pcola LUG,  April 01 2008
Submitted by Peter N.M. Hansteen   [Respond | View]

I'm happy to hear you liked the book overall.

If you found errors, I would be very interested in hearing about them so I can make corrections for any later revs or issue errata. My email address is not a secret, and I'll read any feedback I get and act on what I feel is worthwhile.

All the best,
Peter


PF review by Pcola LUG,  March 08 2008
Rating: StarStarStarStarStar
Submitted by Anonymous Reader   [Respond | View]

Mr. Hansteen, Did a rather good job of putting this book together. The chapters flowed well and one led into the next in a very logical manner. I especially found useful the sections on Round-robin and setting up wireless (Chapter 4 and 7).
Although I make a business of building firewalls I will be keeping this book close at hand. Sadly I only gave 3 stars as I felt the editing could have been better I found several errors with the sample scripts and rules and found it lacking with one or two advanced areas for the professionals would have made this a 5 star easy.


Read all reviews


Media reviews
"This book should be in any well-stocked bookshelf."
-- Axel Gruner, BSDWiki


"All in all, this book is very readable and a must-have resource for anyone who deals with firewall configurations. If you've heard good things about PF and have been thinking of giving it a go, this book is definitely for you. Start at the beginning and before you know it you'll be through the book and quite the PF guru. Even if you're already a PF guru, this is still a good book to keep on the shelf to refer to in thorny situations or to lend to colleagues."
-- Dru Lavigne, Technical Writer



Read all reviews

The Book of PF
See larger cover