firewall choice

Chris bsd-lists at bsdforge.com
Fri Nov 27 09:16:39 UTC 2020


On 2020-11-27 00:29, tech-lists wrote:
> Hi,
> 
> What's the "best" [1] choice for firewalling these days, in the list's 
> opinion?

I can't speak for the whole list. ;-)
But in my opinion with tables totaling over 150 million IPs. I'm casting a 
vote
for pf(4). It's wildly easy on resources and as fast and flexible as I could 
ever
hope to want. Started using it years ago, and never looked back. :-)

> 
> There's pf, ipf and ipfw. Which is the one being most recently 
> developed/updated?
> I'm used to using pf, have done for over a decade. But OpenBSD's pf has 
> diverged a
> lot more from when it first came across. There seems to be a lot more 
> options.
> Is FreeBSD's pf being actively developed still?

Yes. It is actively developed.
> 
> ipfw seems a lot more syntatically complex than pf. Is it more capable also?
> I know nothing about ipf yet.
> 
> [1] up-to-date, versatile, low overhead, high throughput, IPv6-able,
> traffic shaping/queueing
> 
> thanks,

--Chris


More information about the freebsd-current mailing list