Subject: Re: pf status
To: Wolfgang S. Rupprecht <>
From: Peter Postma <>
List: current-users
Date: 07/28/2005 15:39:02
On Wed, Jul 27, 2005 at 02:55:28PM -0700, Wolfgang S. Rupprecht wrote:
> What is the current status of PF (the packet filter) in netbsd?
> I've gotten hooked on pf's hash-tables for efficiently blocking
> chronic offenders.

It's available in 2.0 by using the PF LKM (see pkgsrc/security/pflkm).

In 3.0 and -current it's available in the base system. You can compile
it into the kernel (pseudo-device pf) or use the LKM: /usr/lkm/pf.o.

Almost all features are supported with the exception of ALTQ (but there is
ongoing work on this, meanwhile see:

Peter Postma