Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 4 Nov 2020 22:40:32 +0100
From:      Mateusz Piotrowski <0mp@FreeBSD.org>
To:        Paul Pathiakis <pathiaki2@yahoo.com>, Thomas Laus <lausts@acm.org>
Cc:        "freebsd-virtualization@freebsd.org" <freebsd-virtualization@freebsd.org>
Subject:   Re: Using OpenBSD guest as PF firewall
Message-ID:  <b0aa514b-abb1-983b-c864-2e9d080b4f55@FreeBSD.org>
In-Reply-To: <1520318938.1718710.1604519358758@mail.yahoo.com>
References:  <01000175941a2783-79804ed8-eafa-4f80-92d4-3f500e9d7993-000000@email.amazonses.com> <974524126.1643642.1604508967098@mail.yahoo.com> <0100017594cd88fb-b5e708e7-8213-4c8e-9446-9b1a28fb2a61-000000@email.amazonses.com> <1520318938.1718710.1604519358758@mail.yahoo.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On 11/4/20 8:49 PM, Paul Pathiakis via freebsd-virtualization wrote:
>   Thank you.
> I didn't know they had never 're-synced'.
> Paul

Just for the record, the pf version currently available in FreeBSD is not just an old OpenBSD pf. 
See the note in the PF chapter in the handbook (https://www.freebsd.org/doc/handbook/firewalls-pf.html):

"Warning:

When reading the PF FAQ, keep in mind that FreeBSD's version of PF has diverged substantially from 
the upstream OpenBSD version over the years. Not all features work the same way on FreeBSD as they 
do in OpenBSD and vice versa."

Cheers!

>
>      On Wednesday, November 4, 2020, 2:48:20 PM EST, Thomas Laus <lausts@acm.org> wrote:
>   
>   Paul Pathiakis [pathiaki2@yahoo.com] wrote:
>>    Hi,
>> Is there a reason you would want to use OpenBSD versus FreeBSD?
>> FreeBSD has pf and I use it on my server at home.
>>
>> Are you exploring OpenBSD? Did you not know that pf is an
>> available firewall on FreeBSD?
>>
> The OpenBSD PF firewall is several revisions ahead and more inte-
> grated than one in FreeBSD.  The PF versions diverged in OpenBSD
> 4.7 and the one in FreeBSD was left behind.  I use them both
> on their respected OS.  It was very recent in bhyve development
> that pci-passthru was finally operational with an OpenBSD guest
> and I was building a new server and wanted to test things out.
>
> Tom
>




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?b0aa514b-abb1-983b-c864-2e9d080b4f55>