HEADS UP: pf import

From: Max Laier (max_at_love2party.net)
Date: 02/26/04

  • Next message: Julian Elischer: "Re: Testers needed: Joe's MFC of USB code"
    Date: Thu, 26 Feb 2004 05:34:18 +0100
    To: current@freebsd.org
    
    
    

    Hi,

    we started importing OpenBSD's packet filter (pf) from it's port
    (security/pf). The kernel parts are done, though not linked to any
    automatic build. If you want to build it already, you can build from the
    corresponding module directories:
            sys/modules/{pf, pflog, pfsync}

    Make sure to install new and modified headers.

    User of the port should hold off until this is done. The port will no
    longer build with the new headers installed! There is no userland in the
    tree, yet!

    This brings pf from OpenBSD 3.4 with the complete OpenBSD 3.4 function
    set. It was tested from the port for a long time now and brings some
    features that were not available to FreeBSD before. We have reports from
    people successfully running the port (and a preliminarily version of the
    changes committed now) on production-use firewalls and servers.

    To get an idea of pf's power I suggest reading the OpenBSD FAQ about it:
    http://www.openbsd.org/faq/pf/index.html
    or if you prefer a summarize, check out the port status report:
    http://www.freebsd.org/news/status/report-oct-2003-dec-2003.html#Porting-OpenBSD's-pf

    -- 
    Best regards,				| max@love2party.net
    Max Laier				| ICQ #67774661
    http://pf4freebsd.love2party.net/	| mlaier@EFnet
    
    



  • Next message: Julian Elischer: "Re: Testers needed: Joe's MFC of USB code"

    Relevant Pages

    • A possibly simple query about pf on FreeBSD 5.3-RELEASE
      ... After nearly a week of fighting the dual problem of OpenBSD 3.6 release ... on port ssh and did a few tests with different IP addresses ... I am trying to install plone, zope (and a bunch of zope/plone related ... packages) and apache on the machine. ...
      (freebsd-questions)
    • A possibly simple query about pf on FreeBSD 5.3-RELEASE
      ... After nearly a week of fighting the dual problem of OpenBSD 3.6 release ... on port ssh and did a few tests with different IP addresses ... I am trying to install plone, zope (and a bunch of zope/plone related ... packages) and apache on the machine. ...
      (comp.unix.bsd.freebsd.misc)
    • Re: ipf / pf availability in 4.9
      ... and my question was how to get a port to 4.9. ... >> of the ipf rules can not process a script. ... >> What's the relationship between the freebsd ipf and the openbsd ... >> To unsubscribe, send any mail to ...
      (freebsd-questions)
    • Re: Is VLAN still secure ?
      ... >> Erik Jan van Westen wrote: ... >> port that the system is plugged into is a trunk port, ... >> an openbsd system assume identity in a different VLAN? ...
      (comp.security.firewalls)
    • Re: Very limited port redirection setup with pf not working
      ... OpenBSD box never reach the webserver in the first place, ... OpenBSD box can generally reach the web server! ... OpenBSD if for redirection to webserver: ... Connecting from the client to port 80 of the openbsd box gets ...
      (comp.unix.bsd.openbsd.misc)