tech-net archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: update pf



OpenBSD's PF is not maintainable. It got more and more tentacles into
the rest of the OpenBSD network stack. So yes, effectively I think NPF
is the only viable option midterm.

Bad news. PF is a great design and it's quite multiplatform. It is in
Solaris 11.3, Mac OS X 10.7, FreeBSD and DragonFly, pfSense (= FreeBSD)
and probably others. (FreeBSD port is outdated, too)

NPF is missing TPROXY / divert sockets functionality.

--
Gergely EGERVARY



Home | Main Index | Thread Index | Old Index