From owner-freebsd-virtualization@freebsd.org Wed Nov 4 19:48:21 2020 Return-Path: Delivered-To: freebsd-virtualization@mailman.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.nyi.freebsd.org (Postfix) with ESMTP id 8F3DD4648FB for ; Wed, 4 Nov 2020 19:48:21 +0000 (UTC) (envelope-from 0100017594cd88fb-b5e708e7-8213-4c8e-9446-9b1a28fb2a61-000000@amazonses.com) Received: from a48-106.smtp-out.amazonses.com (a48-106.smtp-out.amazonses.com [54.240.48.106]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-SHA256 (128/128 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 4CRHJN3Zv7z49v5 for ; Wed, 4 Nov 2020 19:48:20 +0000 (UTC) (envelope-from 0100017594cd88fb-b5e708e7-8213-4c8e-9446-9b1a28fb2a61-000000@amazonses.com) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple; s=224i4yxa5dv7c2xz3womw6peuasteono; d=amazonses.com; t=1604519299; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version:Content-Type:In-Reply-To:Feedback-ID; bh=46lRPLas+tAsO1LV0mYV7qsn+m8q/4xGNpXEBMndOUc=; b=bxO/Hjp/hLUKo+EXLGv6CxWiroRayd93VbkBqgidcsi33tH6aCPz/27sxwdov5JA x1SgmunrN6WH3+7i3DzMfczcr2prkP2rw+oitEVE0yBRgd1J8a0iPioocde+cJGx/0m qEFPyoAKvxdPX2kaos6UxWGk+f0YrDGYwpQmmJkI= Date: Wed, 4 Nov 2020 19:48:19 +0000 From: Thomas Laus To: Paul Pathiakis Cc: freebsd-virtualization@freebsd.org Subject: Re: Using OpenBSD guest as PF firewall Message-ID: <0100017594cd88fb-b5e708e7-8213-4c8e-9446-9b1a28fb2a61-000000@email.amazonses.com> References: <01000175941a2783-79804ed8-eafa-4f80-92d4-3f500e9d7993-000000@email.amazonses.com> <974524126.1643642.1604508967098@mail.yahoo.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <974524126.1643642.1604508967098@mail.yahoo.com> X-Operating-System: FreeBSD 12.1-RELEASE-p10 on an amd64 X-SES-Outgoing: 2020.11.04-54.240.48.106 Feedback-ID: 1.us-east-1.9pbSdi8VQuDGy3n7CRAr3/hYnLCug78GrsPo0xSgBOs=:AmazonSES X-Rspamd-Queue-Id: 4CRHJN3Zv7z49v5 X-Spamd-Bar: --- Authentication-Results: mx1.freebsd.org; dkim=pass header.d=amazonses.com header.s=224i4yxa5dv7c2xz3womw6peuasteono header.b=bxO/Hjp/; dmarc=none; spf=pass (mx1.freebsd.org: domain of 0100017594cd88fb-b5e708e7-8213-4c8e-9446-9b1a28fb2a61-000000@amazonses.com designates 54.240.48.106 as permitted sender) smtp.mailfrom=0100017594cd88fb-b5e708e7-8213-4c8e-9446-9b1a28fb2a61-000000@amazonses.com X-Spamd-Result: default: False [-3.41 / 15.00]; ARC_NA(0.00)[]; FORGED_SENDER(0.30)[lausts@acm.org,0100017594cd88fb-b5e708e7-8213-4c8e-9446-9b1a28fb2a61-000000@amazonses.com]; R_DKIM_ALLOW(-0.20)[amazonses.com:s=224i4yxa5dv7c2xz3womw6peuasteono]; NEURAL_HAM_MEDIUM(-1.04)[-1.035]; FROM_HAS_DN(0.00)[]; TO_DN_SOME(0.00)[]; R_SPF_ALLOW(-0.20)[+ip4:54.240.0.0/18:c]; NEURAL_HAM_LONG(-1.05)[-1.049]; MIME_GOOD(-0.10)[text/plain]; DMARC_NA(0.00)[acm.org]; TO_MATCH_ENVRCPT_SOME(0.00)[]; DKIM_TRACE(0.00)[amazonses.com:+]; RCPT_COUNT_TWO(0.00)[2]; RCVD_IN_DNSWL_NONE(0.00)[54.240.48.106:from]; NEURAL_HAM_SHORT(-1.12)[-1.123]; FREEMAIL_TO(0.00)[yahoo.com]; RCVD_COUNT_ZERO(0.00)[0]; RWL_MAILSPIKE_POSSIBLE(0.00)[54.240.48.106:from]; MIME_TRACE(0.00)[0:+]; ASN(0.00)[asn:14618, ipnet:54.240.48.0/23, country:US]; FROM_NEQ_ENVFROM(0.00)[lausts@acm.org,0100017594cd88fb-b5e708e7-8213-4c8e-9446-9b1a28fb2a61-000000@amazonses.com]; MAILMAN_DEST(0.00)[freebsd-virtualization] X-BeenThere: freebsd-virtualization@freebsd.org X-Mailman-Version: 2.1.33 Precedence: list List-Id: "Discussion of various virtualization techniques FreeBSD supports." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 04 Nov 2020 19:48:21 -0000 Paul Pathiakis [pathiaki2@yahoo.com] wrote: > Hi, > Is there a reason you would want to use OpenBSD versus FreeBSD? > FreeBSD has pf and I use it on my server at home. > > Are you exploring OpenBSD? Did you not know that pf is an > available firewall on FreeBSD? > The OpenBSD PF firewall is several revisions ahead and more inte- grated than one in FreeBSD. The PF versions diverged in OpenBSD 4.7 and the one in FreeBSD was left behind. I use them both on their respected OS. It was very recent in bhyve development that pci-passthru was finally operational with an OpenBSD guest and I was building a new server and wanted to test things out. Tom -- Public Keys: PGP KeyID = 0x5F22FDC1 GnuPG KeyID = 0x620836CF