[OT] ipfw or ipfilter ... Re: modifying ipfw rules to accompany dnscache install

Giorgos Keramidas keramida at ceid.upatras.gr
Fri May 2 08:22:10 PDT 2003


On 2003-05-01 23:10, Joe Sotham <joe-dated-1052460660.ce527e at dubium.com> wrote:
>> I'm using ipfilter now, so I haven't run any recent tests with this
>> ruleset, but the rule shown above used to work great.
>
> First, Giorgos, thanks for the reply.
>
> Now I have been pondering the issue of using ipfw or ipfilter but
> haven't seen much discussion in the list.  Is there an issue at all or
> personal preference to which to use.

I like both.  I have used both and feel comfortable with both.  They
both have advantages and disadvantages, so I'll refrain from a long and
pointless description of pros and cons.  There are a lot of messages in
the list archives that address this topic :)

If you're asking why I said that I'm using ipfilter now, it's because of
an earlier attempt to read the source code of ipfilter for educational
purposes.  Setting things to use ipfilter was an easy way to test and
verify that my understanding of the source was correct.

- Giorgos



More information about the freebsd-questions mailing list