From owner-freebsd-ipfw@FreeBSD.ORG Tue Nov 18 17:05:19 2003 Return-Path: Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 4432116A4CE for ; Tue, 18 Nov 2003 17:05:19 -0800 (PST) Received: from rwcrmhc11.comcast.net (rwcrmhc11.comcast.net [204.127.198.35]) by mx1.FreeBSD.org (Postfix) with ESMTP id E380043F75 for ; Tue, 18 Nov 2003 17:05:17 -0800 (PST) (envelope-from cristjc@comcast.net) Received: from blossom.cjclark.org (12-234-156-182.client.attbi.com[12.234.156.182]) by comcast.net (rwcrmhc11) with ESMTP id <2003111901051701300es428e>; Wed, 19 Nov 2003 01:05:17 +0000 Received: from blossom.cjclark.org (localhost. [127.0.0.1]) by blossom.cjclark.org (8.12.9p2/8.12.8) with ESMTP id hAJ15asb011376; Tue, 18 Nov 2003 17:05:36 -0800 (PST) (envelope-from cristjc@comcast.net) Received: (from cjc@localhost) by blossom.cjclark.org (8.12.9p2/8.12.9/Submit) id hAJ15ZXQ011375; Tue, 18 Nov 2003 17:05:35 -0800 (PST) (envelope-from cristjc@comcast.net) X-Authentication-Warning: blossom.cjclark.org: cjc set sender to cristjc@comcast.net using -f Date: Tue, 18 Nov 2003 17:05:35 -0800 From: "Crist J. Clark" To: Max Laier Message-ID: <20031119010535.GC10828@blossom.cjclark.org> References: <030101c3ad34$79ad48d0$110d3ad4@VAHOXP> <671461625.20031118142929@love2party.net> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <671461625.20031118142929@love2party.net> User-Agent: Mutt/1.4.1i X-URL: http://people.freebsd.org/~cjc/ cc: freebsd-ipfw@freebsd.org cc: Vahric MUHTARYAN Subject: Re: Which Firewall --> ipfw or iptable or ipsec X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: "Crist J. Clark" List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 19 Nov 2003 01:05:19 -0000 On Tue, Nov 18, 2003 at 02:29:29PM +0100, Max Laier wrote: [snip] > 2) IPFILTER (a bit dated but with quite a few FAQs around) > 3) PF: security/pf (from ports. The OpenBSD FAQ is a good starting > point to learn about it's capabilities: > http://www.openbsd.org/faq/pf/index.html) > > For case 2) & 3) you'll need "option PFIL_HOOKS" in your kernel, which > is - sadly enough - not (yet) in GENERIC. You do not need PFIL_HOOKS for the 4_RELENG branch (FreeBSD 4.x). Starting with 5.2 you will not need it in the 5.x branch either. -- Crist J. Clark | cjclark@alum.mit.edu | cjclark@jhu.edu http://people.freebsd.org/~cjc/ | cjc@freebsd.org