From owner-freebsd-pf@FreeBSD.ORG Mon Mar 31 22:18:26 2008 Return-Path: Delivered-To: freebsd-pf@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 539091065671 for ; Mon, 31 Mar 2008 22:18:26 +0000 (UTC) (envelope-from Greg.Hennessy@nviz.net) Received: from smtp1.betherenow.co.uk (smtp1.betherenow.co.uk [87.194.0.68]) by mx1.freebsd.org (Postfix) with SMTP id E480B8FC1B for ; Mon, 31 Mar 2008 22:18:15 +0000 (UTC) (envelope-from Greg.Hennessy@nviz.net) Received: from gw2.local (87-194-161-157.bethere.co.uk [87.194.161.157]) by smtp1.betherenow.co.uk (Postfix) with SMTP id 633CE2923A4 for ; Mon, 31 Mar 2008 22:53:26 +0100 (BST) From: "Greg Hennessy" To: "'Rance Hall'" , References: <845c0f80803311151y7fcd3e77r836a5026d76b5179@mail.gmail.com> <1206992159.2108.23.camel@kensho.c7.ca> <845c0f80803311316k7a34bf5bq8b1638581a78e53@mail.gmail.com> In-Reply-To: <845c0f80803311316k7a34bf5bq8b1638581a78e53@mail.gmail.com> Date: Mon, 31 Mar 2008 22:53:17 +0100 Message-ID: <000001c89379$a0dccd10$e2966730$@Hennessy@nviz.net> MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit X-Mailer: Microsoft Office Outlook 12.0 Thread-Index: AciTbqe+gpz2ctYuQ82YmW1mB93KzAACq2Sg Content-Language: en-gb x-cr-hashedpuzzle: 3zw= AtHN BIyi B78S B+38 DBTA DdQy F/Jy GfLY Kl+q MfDA N+S8 PQMW PSCt PtPE QW0I; 2; ZgByAGUAZQBiAHMAZAAtAHAAZgBAAGYAcgBlAGUAYgBzAGQALgBvAHIAZwA7AHIAYQBuAGMAZQBoAEAAZwBtAGEAaQBsAC4AYwBvAG0A; Sosha1_v1; 7; {104AEF43-4417-4C28-97C0-AC7FA206AC29}; ZwByAGUAZwAuAGgAZQBuAG4AZQBzAHMAeQBAAG4AdgBpAHoALgBuAGUAdAA=; Mon, 31 Mar 2008 21:53:13 GMT; UgBFADoAIABuAGUAZQBkACAAaABlAGwAcAAgAGYAaQBnAHUAcgBpAG4AZwAgAG8AdQB0ACAAaQBmACAAcABmACAAaQBzACAAcgBpAGcAaAB0ACAAZgBvAHIAIABtAGUALgA= x-cr-puzzleid: {104AEF43-4417-4C28-97C0-AC7FA206AC29} X-Antivirus: avast! (VPS 080331-0, 31/03/2008), Outbound message X-Antivirus-Status: Clean Cc: Subject: RE: need help figuring out if pf is right for me. X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 31 Mar 2008 22:18:26 -0000 > but look at the other option, somehow feed the constructed rules into > pfctl dynamically as they are "interpreted" By that statement, you really need to forget everything you know about IPTables and read the relevant PF documentation, in particular the man page for pfctl, unlike other unix like operating systems, the man pages on *BSDs usually contain *all* the information you need to configure something in an appropriate manner. Regards Greg