From owner-freebsd-net Wed May 8 15:34: 8 2002 Delivered-To: freebsd-net@freebsd.org Received: from cairo.anu.edu.au (cairo.anu.edu.au [150.203.224.11]) by hub.freebsd.org (Postfix) with ESMTP id 457A437B400; Wed, 8 May 2002 15:34:01 -0700 (PDT) Received: from cairo.anu.edu.au (localhost [127.0.0.1]) by cairo.anu.edu.au (8.12.0/8.12.0) with ESMTP id g48MXv3g024458; Thu, 9 May 2002 08:33:57 +1000 (EST) Received: (from avalon@localhost) by cairo.anu.edu.au (8.12.0/8.12.0.Beta16) id g48MXtIK024453; Thu, 9 May 2002 08:33:55 +1000 (EST) From: Darren Reed Message-Id: <200205082233.g48MXtIK024453@cairo.anu.edu.au> Subject: Re: ipf vs. ipfw To: tal@lumeta.com (Tom Limoncelli) Date: Thu, 9 May 2002 08:33:55 +1000 (Australia/NSW) Cc: freebsd-security@FreeBSD.ORG, freebsd-net@FreeBSD.ORG In-Reply-To: <3CD95E0F.A3E7398C@lumeta.com> from "Tom Limoncelli" at May 08, 2002 01:19:11 PM X-Mailer: ELM [version 2.5 PL1] MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit Sender: owner-freebsd-net@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org In some mail from Tom Limoncelli, sie said: > > Thanks to everyone that answered my questions. As in true Usenet > tradition, if you want the full story, post a message with a lot of > incorrect statements. I got much better results than the carefully thought > out queries that I had sent to various people. :-) > > I've updated my page > http://whatexit.org/tal/mywritings/freefilters.html The line entry for pf is wrong. It is defaintely not a superset of IPFilter or ipfw or any of the other free packet filtering systems. It should simply say pf includes the listed features. You also do not mention SunScreen. Version 3.1(Lite) came with Solaris8, 3.2 will be bundled with Solaris9 (don't know if this is the Lite version or not). Don't know if anyone actually uses it, either. Darren To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-net" in the body of the message