From owner-freebsd-questions@FreeBSD.ORG Wed Jul 30 19:17:46 2014 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1 with cipher ADH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 88D86A7D for ; Wed, 30 Jul 2014 19:17:46 +0000 (UTC) Received: from skapet.bsdly.net (unknown [IPv6:2001:16d8:ff00:1a9::2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 40B4E290E for ; Wed, 30 Jul 2014 19:17:45 +0000 (UTC) Received: from [192.168.103.72] (helo=elke.bsdly.net) by skapet.bsdly.net with esmtp (Exim 4.82_1-5b7a7c0-XX) (envelope-from ) id 1XCZNc-0001Dt-J5; Wed, 30 Jul 2014 21:17:41 +0200 To: freebsd-questions@freebsd.org Subject: Re: Future of pf / firewall in FreeBSD ? - does it have one ? References: <53D1BFB5.60804@herveybayaustralia.com.au> From: peter@bsdly.net (Peter N. M. Hansteen) Date: 30 Jul 2014 21:17:34 +0200 In-Reply-To: <53D1BFB5.60804@herveybayaustralia.com.au> Message-ID: <87egx2slkh.fsf@elke.bsdly.net> Lines: 20 User-Agent: Gnus/5.09 (Gnus v5.9.0) Emacs/21.4 MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.18 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 30 Jul 2014 19:17:46 -0000 Da Rock writes: > Jumping in to this little fray... you're exactly right. But the handbook > for pf says to go to openbsd for "better" info on how to setup pf, which > then has instructions using a syntax that doesn't exist on FreeBSD. This > is not just about google searches - although users end up going there > because of the syntax issues. That was the case for a long time, but fortunately if you take a peek at http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/firewalls-pf.html now, it has a lot more text than it used to (based on my pf tutorial, but extensively massaged by others) and an explicit warning on top about the syntax differences. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.