Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 28 Nov 2020 22:48:02 -0500
From:      grarpamp <grarpamp@gmail.com>
To:        freebsd-current@freebsd.org
Subject:   Re: firewall choice
Message-ID:  <CAD2Ti29Vyqbp9enZ%2BPKNOvKmCXzpfC1yrPN990fHSD3ifVkNag@mail.gmail.com>
In-Reply-To: <202011280626.0AS6QAbC032721@slippy.cwsent.com>
References:  <X8C43AprLKhr3xxy@rpi4.local> <CAD2Ti28csaoinhD_4Cx2S9f89m%2B6mtq7YetitM7Z-RHpPonY4Q@mail.gmail.com> <X8ET90gWvqFMAdwy@rpi4.local> <CAD2Ti2_%2B5fy_fP1EVJwFpa484L7hJCcgA1zO6qgJhpUXOZ7WqQ@mail.gmail.com> <202011280626.0AS6QAbC032721@slippy.cwsent.com>

next in thread | previous in thread | raw e-mail | index | archive | help
> in reaction to the license

Yes, license matters, and woe the history.

> It's hardly deprecated in NetBSD. Christos Zoulas and I have exchanged a
> fair bit of code.
>
> Darren Reed released and maintained IPF through the Australian National
> University. NetBSD imported it, like we do here at FreeBSD, into their src
> tree.

Past tense. Upstream appears dead, for years.

http://netbsd.org/docs/
search: deprecat

ipf (and pf) is deprecated in NetBSD in favor of npf, various
NetBSD docs, manpages, etc say this in different places and
ways, ultimately imparting in sum the shift to npf.
NPF seems the forward looking ongoing concern filter in NetBSD.

DR hasn't cut a ipf release since 5.1.2 almost a decade ago,
and all the project release websites lists for ipf appear gone.
And it's been hampered by license problems,
just like xf86, qmail, bsd, nprobe, zfs, etc.
There are cases of too much history weighing opensource projects.

Distributed maintenance and exchange is certainly cool, but ipf diffs
exist, and users should perhaps not view that model as a formal
cross platform ongoing project such as they may be accustomed to.

That actually gives rise to what a brand new clean slate startup
2-clause fully featured cross platform packet filter of the future
might look like, for at least the BSD's (maybe working on Linux
too). But that's a separate conversation.

So for now, the BSD's (and Linux) really enjoy a mashup
of filters where none have really made it cross platform
and in sync yet.

Perhaps a broad scope wiki comparison would show that,
and end up pointing out the interesting opportunity therein.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CAD2Ti29Vyqbp9enZ%2BPKNOvKmCXzpfC1yrPN990fHSD3ifVkNag>