script to build a firewall appliance based on OpenBSD
Shell C++ DIGITAL Command Language xBase
Pull request Compare This branch is 14 commits behind Eurospider:master.
Fetching latest commit…
Cannot retrieve the latest commit at this time.
Permalink
Failed to load latest commit information.
config
docs
hardware
template
.gitignore
BUGS
COPYING
README.md
TODOS
build.sh

README.md

OpenBSD firewall via scripts

History

Earlier versions of this project were used at Eurospider by Mihai Barbos (https://github.com/mbarbos) to build corporate-style firewalls with Portwell hardware.

Newer versions run on Soekris hardware now.

I (https://github.com/andreasbaumann/) merely collected the ideas and updated them to new versions of OpenBSD and cleaned up the repository a little bit. :-)

And I'm using it at home.

Install

Check disk geometry of flash with:

disklabel wd0

Adapt disk geometry in hardware/[machine]/flash_params.

Run 'build.sh [machine] [flash_profile]'.

Transfer image to flash:

dd if=[machine].img of=/dev/wd0c

or remotely (after booting from floppy dongle or from hard disk):

dd if=[machine].img | ssh [machine] "dd of=/dev/wd1c"

Directory layout

  • build.sh: central build script
  • doc: various documentation
  • template: common files with variables being substituted and then copied to the image
  • config: machine-specific configuration (e.g. pf.conf)
  • hardware: flash disk geometry for specific machines

News

15.7.2016:

  • updated to OpenBSD 5.9

17.1.2016:

  • updated to OpenBSD 5.8
  • example shows how to use two nsd's and one unbound to replace a split horizon configuration formerly done with bind views

Roadmap

  • improve update process, preferably an in-situ update via TFTP
  • deal with logging
    • sensord
    • remote syslog
  • various playgrounds
    • ospf, pfsync, carp

Other Embedded OpenBSD projects

possible small OpenBSD makers (low level):

more high-level:

others:

Hardware

At Eurospider we had Portwell NAR-2054 (3 and 5 ethernet port versions), some have VGA ports and USBs, others only COMs, so make sure we always get boot output on COM.

Now at Eurospider we run it on a Soekris net6501.

At home I'm running it on an ALIX.2D13 with 3 LAN ports and a WLAN card.

VirtualBox build and test

Create a VMDK wrapper for the disk image built with 'build.sh firewall-test':

VBoxManage internalcommands createrawvmdk -filename firewall-test.vmdk -rawdisk firewall-test.image

Copy firewall-test.image from OpenBSD machine to the machine running Virtualbox.

Use COM1 and /tmp/serial, host pipe, create pipe in VirtualBox, then:

socat unix-connect:/tmp/serial stdio,raw,echo=0,icanon=0

The network devices is 'em0' not 'reX' on VirtualBox (as opposed to the real box, at the time of writting there is no Realtek ethernet card emulated in VirtualBox).

Troubleshooting

DMA issues

If you get something like

    pciide0:0:0: bus-master DMA error: missing interrupt, status=0x21

then change the access mode from DMA to PIO x See man wd(4) for the values of flags

config -e -u -o /bsd.new /bsd

UKC> change wd
change (y/n) ? y
channel [-1] ? -1
flags [0] ? 0xff0
UKC> quit

mv -f /bsd.new /bsd

Links to guides and documentation