Re: Packet flow through IPFW+IPF+IPNAT ?

From: Brett Glass (brett_at_lariat.org)
Date: 06/01/03

  • Next message: Nickolay A. Kritsky: "Re: IPFW logging brokeness?"
    Date: Sat, 31 May 2003 22:04:24 -0600 (MDT)
    To: duke@irpen.kiev.ua, freebsd-security@freebsd.org
    
    

    I don't use IPFW and IPFilter together, but IIRC IPFilter steps between
    everything else (except for bpf) and the interface. Same for IPNAT, which
    integrates with IPFilter.

    Since the advent of pf and altq, OpenBSD has had a better firewall
    architecture than any of the other BSDs, IMHO. pf can do things which are
    awkward in other systems because features were kludged in later.

    I've always thought that it would be cool to be able to integrate firewall
    components into FreeBSD via its unique NetGraph system. This would let you
    filter specific flows of packets very efficiently.

    --Brett
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Nickolay A. Kritsky: "Re: IPFW logging brokeness?"

    Relevant Pages

    • freebsd 5.4 and ipnat startup problem...?
      ... problems, it was the time to try with 5.4, them i made a fresh freebsd ... I read the handbook to see if something change in the ipfilter ... Copy my ipfilter rules and ipnat rules from my old system to my new ... or freebsd from my firewall but windows cannot, ...
      (freebsd-questions)
    • RE: ipnat+ipfw + 3 gateways
      ... filter rules into IPFILTER. ... IPNAT will not function with out IPFILTER rules. ... > IPFW is an different firewall who has his own NATD function. ...
      (freebsd-questions)
    • RE: What exactly is ipfilter?
      ... FBSD comes with two firewall applications built into the base ... IPFW and IPFILTER. ...
      (freebsd-questions)
    • Re: Fwd: Q: case studies about scalable, enterprise-class firewall w/ IPFilter
      ... I've posted the attached mail in the IP Filter mailing list; ... Subject: Q: case studies about scalable, enterprise-class firewall ... We're currently protecting our network (and as well some FreeBSD ... standalone) with IPFilter... ...
      (freebsd-hackers)
    • RE: Ipfilter 4.1.13 and freebsd 6.1
      ... I am currently running a couple of 6.1 and 5.4 servers as firewall / ... server with ipfilter where it blocks oow packets. ... experiencing problems running it since moving to a 6.1 server. ...
      (freebsd-questions)