From owner-freebsd-current@FreeBSD.ORG Mon Jul 21 05:44:25 2014 Return-Path: Delivered-To: freebsd-current@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 791C762C; Mon, 21 Jul 2014 05:44:25 +0000 (UTC) Received: from mail-oa0-x232.google.com (mail-oa0-x232.google.com [IPv6:2607:f8b0:4003:c02::232]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 346BE26DE; Mon, 21 Jul 2014 05:44:25 +0000 (UTC) Received: by mail-oa0-f50.google.com with SMTP id g18so6646527oah.37 for ; Sun, 20 Jul 2014 22:44:24 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=b+L3Pde+2p5x0v0UjX45Tc99rHgHH4cWZvS9nPvqaog=; b=TCjR2WwQ4HBCIQyCUjmdESvnic+dz8ioYDpDS/mc2B40VZ8jxTKCMp0XPnoR0vlnSD hzGT2TmKst3BpzlzZsgimO9K6Xcwiw/xBlMX65flwwtLzYnWftRHvo+KStwoZXJYeLyw 4KEHhzIZpmaOW+j0YqWJcjc17viWJBLu6adTy6wtW+ThMiWNsViPbOvEd6FioQAPeQ2i jS4RXGKEswsSLmOC4BEG6r/hXUTCnvqH7TFTN8V8ERKbws1oyEKz9nkDxhyG2NeDT77X 67WVW8k9Qjni/7ga08m9P/oHK1bfrHxB/fdV9UVw4Zfkk4ANxe871192wBpuq/2/qHu2 ImUg== MIME-Version: 1.0 X-Received: by 10.182.116.161 with SMTP id jx1mr33664789obb.50.1405921464548; Sun, 20 Jul 2014 22:44:24 -0700 (PDT) Received: by 10.76.170.39 with HTTP; Sun, 20 Jul 2014 22:44:24 -0700 (PDT) In-Reply-To: <20140721.074105.74747815.sthaug@nethelp.no> References: <20140720134133.1d30f725@kan> <20140721.074105.74747815.sthaug@nethelp.no> Date: Mon, 21 Jul 2014 07:44:24 +0200 Message-ID: Subject: Re: Future of pf / firewall in FreeBSD ? - does it have one ? From: Andreas Nilsson To: sthaug@nethelp.no Content-Type: text/plain; charset=UTF-8 X-Content-Filtered-By: Mailman/MimeDel 2.1.18 Cc: Maxim Khitrov , Current FreeBSD , Mailinglists FreeBSD X-BeenThere: freebsd-current@freebsd.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: Discussions about the use of FreeBSD-current List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 21 Jul 2014 05:44:25 -0000 On Mon, Jul 21, 2014 at 7:41 AM, wrote: > > Also, the openbsd stack has some essential features missing in freebsd, > > like mpls and md5 auth for bgp sessions. > > I use MD5 auth for BGP sessions every day (and have been doing so for > several releases). One could definitely wish for better integration - > having to specify MD5 key both in /etc/ipsec.conf and in the Quagga > bgpd config is not nice. But it works. > As far as I know you can only send out correctly authed stuff but not validate incoming. Has that changed? /Andreas > > MPLS would be nice - but is not a high priority. That's what I use > Juniper and Cisco routers for. For MPLS to be of any use I'd also need > a working IS-IS implementation, and I believe Quagga isn't quite there > yet. > > Steinar Haug, Nethelp consulting, sthaug@nethelp.no >