From owner-freebsd-questions@FreeBSD.ORG Thu Dec 4 23:05:50 2003 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 2BA3E16A4CE for ; Thu, 4 Dec 2003 23:05:50 -0800 (PST) Received: from ns.akakom.ac.id (ns.akakom.ac.id [202.95.157.18]) by mx1.FreeBSD.org (Postfix) with ESMTP id 8CE4743F85 for ; Thu, 4 Dec 2003 23:05:45 -0800 (PST) (envelope-from ald72007@akakom.ac.id) Received: from ns.akakom.ac.id (localhost.akakom.ac.id [127.0.0.1]) by ns.akakom.ac.id (8.12.10/8.12.10) with ESMTP id hB575RJh009977; Fri, 5 Dec 2003 14:05:27 +0700 Received: from localhost (ald72007@localhost)hB575Qml009974; Fri, 5 Dec 2003 14:05:27 +0700 X-Authentication-Warning: ns.akakom.ac.id: ald72007 owned process doing -bs Date: Fri, 5 Dec 2003 14:05:26 +0700 (WIT) From: Dwi Suharto To: Emmanuel Gravel In-Reply-To: <1070602696.3909.9.camel@hades> Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII cc: freebsd-questions@freebsd.org Subject: Re: What exactly is ipfilter? X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 05 Dec 2003 07:05:50 -0000 On Thu, 4 Dec 2003, Emmanuel Gravel wrote: > I'm looking through rc.conf and the kernel config file for FreeBSD 4.9 > (recently downloaded it, my last upgrade was 4.5 so I was way behind, > and this is a new install because my old firewall died). I'm used to > using ipfw and natd for my firewall, but now I'm seeing ipfilter, ipnat > and ipmon. I've done a google search on all of www.freebsd.org for > ipfilter, but it only seems to show up in release notes, and the online > handbook doesn't really talk about it. Since I haven't recompiled my new > kernel, should I consider this instead of ipfw and natd? What's the > difference, exactly? > > On a related note, I'm not sure what the usefulness of IPDIVERT is > either, so I don't know if I should compile it in the kernel or not. i'm currently using ipf and ipnat for firewall. you can check this URL for ipf: http://www.obfuscation.org/ipf/ipf-howto.html#TOC_5 --- Dwi Suharto System Engineer and Computer Network Technical Support STMIK AKAKOM Yogyakarta Phone: +62-274-486664 ext. 192 Mobile: +62-8562836982 http://get.bounceme.net/