dslreports logo
site
 
    All Forums Hot Topics Gallery
spc

spacer




how-to block ads


Search Topic:
uniqs
300
share rss forum feed view:
normal


Drunkula
Premium
join:2000-06-12
Denton, TX
Reviews:
·Verizon FiOS

FreeBSD and firewall question

Quick question... Which of the 3 firewalls available in FreeBSD should be used? PF, IPFilter, or IPFW? This is just going to be protecting the one workstation. It won't be used for routing/NATing. It's been quite awhile since I've used any of the BSDs.
--
There are 10 types of people that understand binary numbers. Those that do - and those that do not...



graysonf
Premium,MVM
join:1999-07-16
Fort Lauderdale, FL

See: »cipitunk.wordpress.com/2007/07/0···w-vs-pf/



Drunkula
Premium
join:2000-06-12
Denton, TX

1 edit
reply to Drunkula

Thanks for the link!

EDIT:
Looks like ipfw it is. IIRC that is what I used before.


Bink
Villains... knock off all that evil

join:2006-05-14
Denver, CO
kudos:4

1 recommendation

reply to Drunkula

I find pf's syntax to be easier to understand and I like its single configuration file.



Drunkula
Premium
join:2000-06-12
Denton, TX
reply to Drunkula

On reading a little more I think I'll give pf a shot.



scrummie02
Bentley
Premium
join:2004-04-16
Arlington, VA
reply to Drunkula

PF for sure. It has a rich feature set and some good stuff will be released in FBSD 10. I think I might be switching my OpenBSD firewall over to FreeBSD when 10 is released.



Drunkula
Premium
join:2000-06-12
Denton, TX

1 recommendation

reply to Drunkula

I got to say I am digging PF so far. Very flexible, easy to understand rules...



graysonf
Premium,MVM
join:1999-07-16
Fort Lauderdale, FL

Is this a stand alone firewall running FreeBSD's pf or is the box also used for other purposes?



Drunkula
Premium
join:2000-06-12
Denton, TX
Reviews:
·Verizon FiOS
reply to Drunkula

Just a stand-alone box to handle SSH connections. That is all it'll be used for... A repurposed XP box that I no longer had use for as it were.
--
There are 10 types of people that understand binary numbers. Those that do - and those that do not...



Count Zero
Obama-Biden 2012
Premium
join:2007-01-18
Winston Salem, NC

Check out pfSense (»www.pfsense.org) - I run it as my firewall. Very capable and lots of good add-on packages!