tech-net archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
Re: update pf
In article <cf31885d-121e-5686-d4b7-d5ff8af8a211%egervary.hu@localhost>,
Egerváry Gergely <gergely%egervary.hu@localhost> wrote:
>> OpenBSD's PF is not maintainable. It got more and more tentacles into
>> the rest of the OpenBSD network stack. So yes, effectively I think NPF
>> is the only viable option midterm.
>
>Bad news. PF is a great design and it's quite multiplatform. It is in
>Solaris 11.3, Mac OS X 10.7, FreeBSD and DragonFly, pfSense (= FreeBSD)
>and probably others. (FreeBSD port is outdated, too)
>
>NPF is missing TPROXY / divert sockets functionality.
Can't you use map for those?
christos
Home |
Main Index |
Thread Index |
Old Index