Re: Future of pf / firewall in FreeBSD ? - does it have one ?

From: Franco Fichtner <franco_at_lastsummer.de>
Date: Mon, 21 Jul 2014 23:48:49 +0200
Hi Julian,

On 21 Jul 2014, at 05:15, Julian Elischer <julian_at_freebsd.org> wrote:

> Most people I talk to just use ipfw and couldn't care whether pf lives or dies.  They have simple requirements and almost any filter would suffice.  I haven't found anything I'd want to use pf for that ipfw doesn't allow me to do. There are things pf does that ipfw doesn't... I just never want them..

this is quite insightful.  The gist of this discussion and the apparent
lack of upgrades to pf(4) seem to indicate that:

(a) other packet filters do the required jobs equally or better
    or performance doesn't matter at all.

(b) for more progressive setups and requirements, FreeBSD servers
    may as well be complemented with commercial firewalls, hand-rolled
    or non-FreeBSD solutions

Is that somewhat accurate, or is there more to the story?


Cheers,
Franco
Received on Mon Jul 21 2014 - 19:48:57 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:40:51 UTC