setjmp/lonjmp

Cameron Murdoch cameron at macaroon.net
Sun Feb 13 14:43:17 PST 2005


037632.9040502 at xxxxxxx>	<4203b709$0$718$415eb37d at xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>	<420499A1.5070801 at xxxxxxx>	<420e4e39$0$715$415eb37d at xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>	<420F6729.9090901 at xxxxxxx> <86psz4dxbq.fsf at xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
In-Reply-To: <86psz4dxbq.fsf at xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
Content-Type: text/plain; charset=ISO-8859-15; format=flowed
Content-Transfer-Encoding: 8bit
Lines: 31
Message-ID: <420fd805$0$717$415eb37d at xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx>
NNTP-Posting-Host: 82.109.154.114
X-Trace: 1108334598 crater_reader.dragonflybsd.org 717 82.109.154.114
Xref: crater_reader.dragonflybsd.org dragonfly.kernel:7699

Eric Masson wrote:
> 
> - AltQ is used by Free/Net/Open/DFly
> - PF is used by Free/Net/Open/DFly and KAME project uses it as a packet
>   classifier for AltQ and ipsec engine. 
> - Integrated PF/AltQ has a *really* clear and concise setup file.
> - *Useful* docs are available easily.
> - PF is the only packet filter that has been locked easily for smpng in
>   FreeBSD-5 and later, thanks to a clean codebase. So it should be easy
>   for DFly developpers to achieve the same goal.
> - Many developpers are working on it and are quite responsive to bug
>   reports or feature requests.
> 
> Check these assertions for ipfw/ipfilter. Enough ?
> 
> Éric Masson
> 

The thing that people often forget about ipfilter is that it is one of 
the only cross platform firewalls around. It runs on all the BSDs + 
Solaris, Linux (I think now), + most other unixs. This is important to 
some people. It is just a shame that development is slow; it does still 
happen but is just very slow.

Note that the pf rule syntax is also quite similar to ipfilter but IMHO 
much improved. I am in the progress of moving my ipfilter firewall to pf 
but only because I want ALTQ.

Cheers,

Cam





More information about the Kernel mailing list