Re: Future of pf / firewall in FreeBSD ? - does it have one ?

看板FB_questions作者時間11年前 (2014/07/21 02:32), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串33/44 (看更多)
On Sun, 20 Jul 2014 13:41:33 -0400, Alexander Kabaev wrote: > It was stated repeatedly by multiple people that FreeBSD's network > stack is way too different from OpenBSD, we support features > OpenBSD doesn't and vice versa, vimage is a good example, which throws a > giant wrench into the plan of following OpenBSD 'as closely as > possible', even as the expense of throwing away all of the SMP work > done in pf to date. The difference between FreeBSD's and OpenBSD's network stack is also a problem that you can hardly compensate by maintaining two versions of pf, one provided with the system, one available via ports (as FreeBSD 10 did with unbound / bind), and you also would have to decide which version ("old" or "new") goes with the OS and which comes from ports. Of course following a "moving target" is much easier to do with ports (higher frequency of changes is possible) than with an OS component, and I should emphasize OS _core_ component, as pf is _very_ tightly integrated with kernel and OS mechanisms. Learning a new syntax is the smallest problem here, and BSD folks (as UNIX people in general) have a great reputation of being able to learn new things, evaluate them, and use them as needed, in comparison to those poor guys over in MICROS~1 land... ;-) -- Polytropon Magdeburg, Germany Happy FreeBSD user since 4.0 Andra moi ennepe, Mousa, ... _______________________________________________ freebsd-questions@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-questions To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org"
文章代碼(AID): #1Jp0iZpv (FB_questions)
討論串 (同標題文章)
完整討論串 (本文為第 33 之 44 篇):
文章代碼(AID): #1Jp0iZpv (FB_questions)