Re: firewall on FreeBSD
From: Alex Zbyslaw (xfb52_at_dial.pipex.com)
Date: 06/26/05
- Previous message: Louis LeBlanc: "Re: Perl 5.8.6 to 5.8.7 upgrade fails IPC tests"
- In reply to: Giorgos Keramidas: "Re: firewall on FreeBSD"
- Next in thread: Giorgos Keramidas: "Re: firewall on FreeBSD"
- Reply: Giorgos Keramidas: "Re: firewall on FreeBSD"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Date: Sun, 26 Jun 2005 22:15:59 +0100 To: Giorgos Keramidas <keramida@ceid.upatras.gr>
Giorgos Keramidas wrote:
>On 2005-06-26 00:40, Alex Zbyslaw <xfb52@dial.pipex.com> wrote:
>
>
>>Paul Schmehl wrote:
>>
>>
>>>pf on freebsd does support the "quick" keyword. The "default"
>>>firewall, ipfw, does not.
>>>
>>>
>>This makes no sense to me. The two firewalls work very differently.
>>
>>[...]
>>
>You describe very nicely the way rules are matched by two of the three
>different firewalls available on FreeBSD. The description, being very
>correct, *does* make sense.
>
>Why do you say that ``This makes no sense to you''
>
>
Maybe I'm misreading something, or taking it out of context, but the
statement "ipfw does not support the quick keyword" makes no sense to
me. For me, it implies that somehow ipfw could (or even should) support
the quick keyword, and that is nonsensical. The way ipfw rules work
there is not only no need to support a quick keyword, but no point in
supporting one because all relevant matches are already quick, by
definition.
Maybe I'm being overly pedantic, but if I had stumbled across this
message in an archive search, and knew nothing about FreeBSD firewalls,
I could easily take it to mean that ipfw was lacking a feature with
respect to pf when, in fact, it wasn't. (There may be plenty of other
reasons for picking one firewall or the other, but the "lack" of a quick
keyword in ipfw isn't one of them).
Am *I* making any more sense, now?
--Alex
_______________________________________________
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org"
- Previous message: Louis LeBlanc: "Re: Perl 5.8.6 to 5.8.7 upgrade fails IPC tests"
- In reply to: Giorgos Keramidas: "Re: firewall on FreeBSD"
- Next in thread: Giorgos Keramidas: "Re: firewall on FreeBSD"
- Reply: Giorgos Keramidas: "Re: firewall on FreeBSD"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Relevant Pages
|