Build a Safe PF Firewall Baseline on FreeBSD
The old IP Filter article in this archive reflects an earlier FreeBSD firewall workflow. For a new FreeBSD host, start with PF and make the first policy deliberately small: retain console access, permit only the services the host provides, and validate the rules before enabling them at boot.
This is a documentation-verified baseline, not a copy-and-paste production policy. Interface names, management networks, service ports, IPv6 needs, and routing requirements vary by host. Apply it first from a console or an out-of-band management path so a typo does not strand an SSH-only system.