Re: firewall on freebsd

From: Michael H. Semcheski (lists_at_immuneit.com)
Date: 06/24/05

  • Next message: Joe: "Re: SMP and networking under FreeBSD 5.3"
    To: freebsd-questions@freebsd.org
    Date: Fri, 24 Jun 2005 11:11:13 -0400
    
    

    On Friday 24 June 2005 10:59 am, Ean Kingston wrote:
    > IPF was written for OpenBSD and later ported to FreeBSD. IPF came into
    > existence because of disagreements between certain members of the OpenBSD
    > team and the author of IPFilter. Filtering is done in the kernel and I
    > believe NAT is also in-kernel.

    The OpenBSD packet filter is known as pf, not ipf. It exists in FreeBSD as
    pf.

    I have to say that I find it has some very useful features, though they are
    outside the mainstream firewall feature set. For instance, authpf. When you
    log into the firewall (usually via ssh), if the account's login type shell is
    authpf, a special set of firewall rules get loaded for the IP address the
    client is connecting from.

    I have used pf and ipfw, and they're both fine. If I had to pick, I'd choose
    pf because I like that it uses a seperate configuration file, rather than a
    shell script to load its rules.

    I'm not an expert on either.

    Mike
    _______________________________________________
    freebsd-questions@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-questions
    To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org"


  • Next message: Joe: "Re: SMP and networking under FreeBSD 5.3"

    Relevant Pages

    • Re: RX (download) limit problem
      ... > I've been seeing a strange problem with my 5.4-STABLE freebsd ... > behind it or the firewall itself) can get a decent rate. ... > In talking to some openBSD guys we had a theory that it might be something ... > the upload and download being kept symmetric and hence so low on the ...
      (freebsd-current)
    • dmz server setup - opinions
      ... firewall will pull data from it to later process. ... Originally i was thinking of using OpenBSD, as it seems to lend itself very ... use FreeBSD, i could jail each process, granted i could also chroot each process ... rsyncd running, only allowing access from the internal network. ...
      (freebsd-questions)
    • Dear god not another *BSD debate (was - hiding OS name)
      ... > JSA> Just because the firewall is OpenBSD do NOT ... > JSA> well tuned and hardened FreeBSD box. ...
      (FreeBSD-Security)
    • Re: Public IP routing
      ... > optional - aka IPless bridge), add the interfaces to the bridge interface ... At the time I needed such a setup, I much prefered IPF ... filtering 'bridged' packets/frames with FreeBSD ... would only work with IPFW and not IPF so I ended up using OpenBSD for this p ...
      (comp.unix.bsd.freebsd.misc)
    • Re: Looking into a new firewall
      ... I would like to move to a Linux ... >> the Checkpoint for Linux or we can look to some other firewall. ... > FreeBSD you can use IPFW or IPF. ... > OpenBSD is great for IPSec too and with support for hardware based crypto ...
      (comp.security.firewalls)