Page MenuHomeFreeBSD

Handbook - Firewalls
Needs ReviewPublic

Authored by carlavilla on Jul 18 2026, 2:10 PM.
Tags
None
Referenced Files
Unknown Object (File)
Thu, Sep 24, 6:44 AM
Unknown Object (File)
Wed, Sep 23, 2:16 AM
Unknown Object (File)
Sun, Sep 13, 2:57 AM
Unknown Object (File)
Fri, Sep 11, 1:17 PM
Unknown Object (File)
Fri, Sep 11, 4:10 AM
Unknown Object (File)
Sat, Sep 5, 4:10 AM
Unknown Object (File)
Fri, Sep 4, 1:07 PM
Unknown Object (File)
Wed, Sep 2, 5:07 PM

Details

Summary

Rework, changes:

  • Add "Choosing a Firewall" comparison section.
  • Add "Traffic Shaping with Dummynet" section, demote ALTQ to a legacy note
  • Rewrite PF examples
  • Add set skip on lo0, syncookies, ICMPv6/NDP guidance, etc
  • Modernize interfaces, mail ports, etc
  • Fix inbound ICMP/ICMPv6 to allow PMTUD and neighbor discovery
  • Trim IPFILTER to pointer-level, compress FTP proxy, drop spamd/greylisting

Diff Detail

Repository
R9 FreeBSD doc repository
Lint
Lint Skipped
Unit
Tests Skipped

Event Timeline

carlavilla created this revision.

Unfortunately, there is very little I can contribute here. My knowledge in regards of all of these FWs is close to zero.

documentation/content/en/books/handbook/firewalls/_index.adoc
871

Though I am not a native speaker, shouldn't it be "which does not require a custom kernel"? Hope a native speak can clarify because the sentence reads awkwardly for me.

carlavilla marked an inline comment as done.
carlavilla added reviewers: emaste, philip, lwhsu, bofh, dbaio, ebrandi.

This is really difficult to review. I wonder if it wants to be several smaller commits instead of one huge one.

An initial observation: do we simply want to get rid of all mentions of FTP? It looks like that's what's happening. Splitting that out into a single commit would already make the rest easier to review.

damjan.jov_gmail.com added inline comments.
documentation/content/en/books/handbook/firewalls/_index.adoc
855

You might also want to mention that ALTQ requires device driver modifications, and not all network devices work with ALTQ, while all work with dummynet. See "man 4 altq" where it gives a list of "supported devices".