From nobody Mon Jul 24 15:47:35 2023 X-Original-To: dev-commits-doc-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4R8l0l6yyWz4nthR for ; Mon, 24 Jul 2023 15:47:35 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4R8l0l6ZK4z3pcM; Mon, 24 Jul 2023 15:47:35 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1690213655; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=KV1n3gppk28Lgf7R2+3r8CsxxZgny6XienDCpXiBUUc=; b=toY7AeE2vOY/hZiW/oTOH6J9XkbseHXecuYNR1eLjqjcvC6LD106ha3BEScDw4t5w+RSZ9 suWi0nq7WbBEmAkx+pQr+NXrJ5V9xAtPOqDjRf1lwGgpuSh7Uav7P1nMAM16Zgo8HccJda 2Z7Lplz6/VDzozuCLatFG99tPFpF6XYQ662QtGo+37tmIAu+9LR9gq7JLvevyBvw7yWIiD JnSuSMBMq3yxgZllb1zWEGhl90inilh1bdssKfIWXW0IEhMbJARpBy94ppWtsIyjxfzxD9 XoUywzcCyTwam0G1ceXgHqIbZmoZ3hr5deO2MrSFYDnJaofv2kZyg9HoIVtCEA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1690213655; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=KV1n3gppk28Lgf7R2+3r8CsxxZgny6XienDCpXiBUUc=; b=QbgCfw+DnBvCkzt+bDeGRUh0VFoM0njQkqdxVV4OyM39JWVj3W6lT/ndaSQQnEl1b4PwG6 no5RUEoL9ZCVimNd2X+/AyPJEBO/aO4eejChBvLkFTMzbjbFBaG2UTDc0vYpilE2jaRZCQ 9cl2F6XSa22Yjrn2axkmaKAk7DiKhH5EkqL1U70cRVYURAKyROPx63zl3izkUwpSk04Fwo ZLexTzM4MxksGQXVAWacxaobSHBeVE1eFGN6OqNpw7QAwAoses+hl8+e6dt14lU/LlWHrq SPEklbBpsEgTEK9oGMcGkEYfuXyXBeW3xRrmR4TR1PjcEHZiy/fXxKR3I77AVw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1690213655; a=rsa-sha256; cv=none; b=r+CAPkaMVqmUWS2jUq0m9Cmt1/VIyVNCM5GWGdrPTAcm9P7ME6ujgHgQL3Guq0oNxwZuDN 7wWtyvDO8wZYyvoh6/IJN6z8B7bYyXbl2JFhcnBKjyVPmV31O1EvazGNuMNr7SLlMO++PL LcYlOjpU2RlfQjhESrd/SIMU5yN8tZQEI1a44OcyFo0rLqQHpFG3F66tLkqOqu3A1OKO82 0mv6AyRXD9SljR3MAvwsQfbTQeI95yv4x+VA1FqTupMAmrNniixLLhr/pToLBQcF/QGkjZ ZAfBdq6zIyfRGClbNbECuADm8kscUj1Jg1OWtyZhI/qz0gV9Uu9/N95T1nIi5A== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4R8l0l5gHhzNp9; Mon, 24 Jul 2023 15:47:35 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 36OFlZmQ080154; Mon, 24 Jul 2023 15:47:35 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 36OFlZY6080153; Mon, 24 Jul 2023 15:47:35 GMT (envelope-from git) Date: Mon, 24 Jul 2023 15:47:35 GMT Message-Id: <202307241547.36OFlZY6080153@gitrepo.freebsd.org> To: doc-committers@FreeBSD.org, dev-commits-doc-all@FreeBSD.org From: Ed Maste Subject: git: 47c2526aa8 - main - 2023q2 status: add pf report List-Id: Commit messages for all branches of the doc repository List-Archive: https://lists.freebsd.org/archives/dev-commits-doc-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-doc-all@freebsd.org X-BeenThere: dev-commits-doc-all@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: emaste X-Git-Repository: doc X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 47c2526aa8a79677befb7817be436837a53fd0d5 Auto-Submitted: auto-generated The branch main has been updated by emaste: URL: https://cgit.FreeBSD.org/doc/commit/?id=47c2526aa8a79677befb7817be436837a53fd0d5 commit 47c2526aa8a79677befb7817be436837a53fd0d5 Author: Ed Maste AuthorDate: 2023-07-21 12:46:30 +0000 Commit: Ed Maste CommitDate: 2023-07-24 15:47:16 +0000 2023q2 status: add pf report Based on kp's original review. Reviewed by: salvadore Differential Revision: https://reviews.freebsd.org/D41111 --- .../en/status/report-2023-04-2023-06/pf.adoc | 45 ++++++++++++++++++++++ 1 file changed, 45 insertions(+) diff --git a/website/content/en/status/report-2023-04-2023-06/pf.adoc b/website/content/en/status/report-2023-04-2023-06/pf.adoc new file mode 100644 index 0000000000..97c9ac69c0 --- /dev/null +++ b/website/content/en/status/report-2023-04-2023-06/pf.adoc @@ -0,0 +1,45 @@ +=== Pf Improvements + +Links: + +link:https://reviews.freebsd.org/D40911[D40911] URL: link:https://reviews.freebsd.org/D40911p[] + +link:https://reviews.freebsd.org/D40861[D40861] URL: link:https://reviews.freebsd.org/D40861p[] + +link:https://reviews.freebsd.org/D40862[D40862] URL: link:https://reviews.freebsd.org/D40862p[] + +link:https://reviews.freebsd.org/D40863[D40863] URL: link:https://reviews.freebsd.org/D40863p[] + +link:https://reviews.freebsd.org/D40864[D40864] URL: link:https://reviews.freebsd.org/D40864p[] + +link:https://reviews.freebsd.org/D40865[D40865] URL: link:https://reviews.freebsd.org/D40865p[] + +link:https://reviews.freebsd.org/D40866[D40866] URL: link:https://reviews.freebsd.org/D40866p[] + +link:https://reviews.freebsd.org/D40867[D40867] URL: link:https://reviews.freebsd.org/D40867p[] + +link:https://reviews.freebsd.org/D40868[D40868] URL: link:https://reviews.freebsd.org/D40868p[] + +link:https://reviews.freebsd.org/D40869[D40869] URL: link:https://reviews.freebsd.org/D40869p[] + +link:https://reviews.freebsd.org/D40870[D40870] URL: link:https://reviews.freebsd.org/D40870p[] + +Contact: Kajetan Staszkiewicz + +Contact: Naman Sood + +Contact: Kristof Provost + +man:pf[4] is one of the firewalls included in FreeBSD, and is probably the most popular. +pf was created by the OpenBSD project and subsequently ported to FreeBSD. + +==== Backport OpenBSD Syntax + +Kajetan introduced the OpenBSD syntax of "scrub" operations in "match" and "pass" rules. +Existing rules remain supported, but now OpenBSD style "scrub" configuration is also supported. + +==== pfsync Protocol Versioning + +The man:pfsync[4] protocol version can now be configured, allowing for protocol changes while still supporting state synchronisation between disparate kernel versions. +The primary benefit is to allow protocol changes enabling new functionality. + +==== pfsync: Transport over IPv6 + +pfsync traffic can now be carried over IPv6 as well. +Naman finished the work started by Luiz Amaral. + +==== SCTP + +There is work in progres to support SCTP in pf. +That support includes filtering on port numbers, state tracking, pfsync failover and returning ABORT chunks for rejected connections. + +Sponsor: InnoGames GmbH +Sponsor: Orange Business Services +Sponsor: The FreeBSD Foundation