content-based firewall

Philip Reynolds philip.reynolds at rfc-networks.ie
Tue May 20 11:34:15 PDT 2003


clemens fischer <ino-qc at spotteswoode.de.eu.org> 20 lines of wisdom included:
> i am interested in this as well.  the only thing in this context i
> remember are the accf_http(9) filters.  is the divert-filtering code
> somewhere publicly accessable?

It's actually part of a project I was working on which has to be
demonstrated on May 27th. The code needs to be tidied up a good bit
before then.

When it is available it'll be placed on my webpage.

The only thing I'd say is that this functionality and better is
available by running a proper firewall ruleset and using internal
mailservers and web proxies. Even a simple tcpdump running in the
background would give you the same functionality, with a bit of
sifting through it.

However, I do see the need (or want) for something a little bit
easier to debug and run. This is more of a proof-of-concept idea,
but I'll certainly leave it available once it's done.

Regards,
-- 
Philip Reynolds                      | RFC Networks Ltd.
philip.reynolds at rfc-networks.ie      | +353 (0)1 8832063
http://people.rfc-networks.ie/~phil  | www.rfc-networks.ie


More information about the freebsd-ipfw mailing list