Re: comparision of firewalling on Linux and FreeBSD

From: Charles Swiger (cswiger_at_mac.com)
Date: 06/30/04

  • Next message: Sten Spans: "Re: FreeVRRPD problem"
    Date: Wed, 30 Jun 2004 13:57:29 -0400
    To: socrel@gmx.net
    
    

    On Jun 30, 2004, at 1:47 PM, socrel@gmx.net wrote:
    > Looking for considered comparisions of firewalling on Linux and
    > FreeBSD.

    Hmm, what you should be considering is whether you want to use pf/IPF,
    or IPFW. If IPFW makes more sense to you, use FreeBSD. If you want to
    use IPF, either platform will do, but I'd still recommend FreeBSD.

    > I am especially interested in learning about ease of connection
    > tracking

    Like what, logging packets with the SYN bit set? IPFW gives you that
    easily.

    > and of getting packets into user space for analysis via scripts.

    The BPF + tools like tcpdump, snort, and whatnot...

    -- 
    -Chuck
    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"
    

  • Next message: Sten Spans: "Re: FreeVRRPD problem"

    Relevant Pages

    • Re: Firewall questions
      ... > "On FreeBSD you have a choice of IPFW, IPF, and PF. ... > IPF runs on many OSes (but not Linux)," ...
      (freebsd-questions)
    • IPFW policy routing...
      ... this case works on Linux but I'm still not able to get it ... works on FreeBSD. ... NAT Address to use with Net1: ... my ipfw configuration, where all is allowed by default. ...
      (freebsd-questions)
    • Re: IpFilter / IpFireWall
      ... except for ones which are related in connections that were established as ... some badly configured servers test for ident (port ... See the security section in the FreeBSD handbook, ... compiling your kernel, and the ipfw manpage, for more details. ...
      (FreeBSD-Security)
    • user based firewalling with ipfw and priviledged ports.
      ... to the FreeBSD platform. ... On the original platform (Linux) I made ... ipfw on FreeBSD untill by change I ran into it while porting to FreeBSD. ...
      (FreeBSD-Security)
    • FreeBSD Security Advisory: FreeBSD-SA-01:08.ipfw [REVISED]
      ... included in FreeBSD 4.0 and above. ... based on an old version of ipfw and does not contain as many features. ... Due to overloading of the TCP reserved flags field, ... incorrectly treat all TCP packets with the ECE flag set as being part ...
      (FreeBSD-Security)