The Book of PF : A No-Nonsense Guide to the OpenBSD Firewall, 2/e (Paperback)

Peter N. M. Hansteen

  • 出版商: No Starch Press
  • 出版日期: 2010-11-22
  • 定價: $990
  • 售價: 5.0$495
  • 語言: 英文
  • 頁數: 216
  • 裝訂: Paperback
  • ISBN: 159327274X
  • ISBN-13: 9781593272746
  • 相關分類: BSD
  • 立即出貨(限量) (庫存=1)

買這商品的人也買了...

商品描述

OpenBSD's stateful packet filter, PF, is the heart of the OpenBSD firewall and a necessity for any admin working in a BSD environment. With a little effort and this book, you'll gain the insight needed to unlock PF's full potential.

This second edition of The Book of PF has been completely updated and revised. Based on Peter N.M. Hansteen's popular PF website and conference tutorials, this no-nonsense guide covers NAT and redirection, wireless networking, spam fighting, failover provisioning, logging, and more. Throughout the book, Hansteen emphasizes the importance of staying in control with a written network specification, keeping rule sets readable using macros, and performing rigid testing when loading new rules.

The Book of PF tackles a broad range of topics that will stimulate your mind and pad your resume, including how to:

  • Create rule sets for all kinds of network traffic, whether it's crossing a simple LAN, hiding behind NAT, traversing DMZs, or spanning bridges or wider networks
  • Create wireless networks with access points, and lock them down with authpf and special access restrictions
  • Maximize flexibility and service availability via CARP, relayd, and redirection
  • Create adaptive firewalls to proactively defend against would-be attackers and spammers
  • Implement traffic shaping and queues with ALTQ (priq, cbq, or hfsc) to keep your network responsive
  • Master your logs with monitoring and visualization tools (including NetFlow)

The Book of PF is for BSD enthusiasts and network administrators at any skill level. With more and more services placing high demands on bandwidth and an increasingly hostile Internet environment, you can't afford to be without PF expertise.

商品描述(中文翻譯)

OpenBSD的有狀態封包過濾器PF是OpenBSD防火牆的核心,對於在BSD環境中工作的任何管理員來說都是必不可少的。通過一點努力和這本書,您將獲得解鎖PF全部潛力所需的洞察力。

這本第二版的《PF之書》已經完全更新和修訂。基於Peter N.M. Hansteen受歡迎的PF網站和會議教程,這本直截了當的指南涵蓋了NAT和重定向、無線網絡、對抗垃圾郵件、故障轉移配置、日誌記錄等內容。在整本書中,Hansteen強調了撰寫網絡規範的重要性,使用宏保持規則集的可讀性,以及在加載新規則時進行嚴格的測試。

《PF之書》涵蓋了一系列主題,將激發您的思維並豐富您的履歷,包括如何:
- 為各種網絡流量創建規則集,無論是跨越簡單的局域網、隱藏在NAT後面、穿越DMZ,還是跨越橋接或更廣泛的網絡。
- 使用接入點創建無線網絡,並使用authpf和特殊訪問限制來鎖定它們。
- 通過CARP、relayd和重定向來最大程度地提高靈活性和服務可用性。
- 創建自適應防火牆,以主動防禦潛在的攻擊者和垃圾郵件發送者。
- 使用ALTQ(priq、cbq或hfsc)實現流量整形和隊列,以保持您的網絡響應靈敏。
- 通過監控和可視化工具(包括NetFlow)掌握您的日誌。

《PF之書》適用於任何技能水平的BSD愛好者和網絡管理員。隨著越來越多的服務對帶寬提出高要求,以及日益惡劣的互聯網環境,您不能沒有PF專業知識。