Page MenuHomeFreeBSD

Handbook - Firewalls
Needs ReviewPublic

Authored by carlavilla on Sat, Jul 18, 2:10 PM.
Tags
None
Referenced Files
F163639898: D58324.id.diff
Sat, Jul 25, 2:26 AM
F163586928: D58324.id182178.diff
Fri, Jul 24, 5:59 PM
F163583449: D58324.id182201.diff
Fri, Jul 24, 5:22 PM
Unknown Object (File)
Fri, Jul 24, 1:46 AM
Unknown Object (File)
Thu, Jul 23, 5:38 AM
Unknown Object (File)
Wed, Jul 22, 10:09 PM
Unknown Object (File)
Wed, Jul 22, 9:30 AM
Unknown Object (File)
Tue, Jul 21, 8:08 PM
Subscribers
None

Details

Summary

Rework, changes:

  • Add "Choosing a Firewall" comparison section.
  • Add "Traffic Shaping with Dummynet" section, demote ALTQ to a legacy note
  • Rewrite PF examples
  • Add set skip on lo0, syncookies, ICMPv6/NDP guidance, etc
  • Modernize interfaces, mail ports, etc
  • Fix inbound ICMP/ICMPv6 to allow PMTUD and neighbor discovery
  • Trim IPFILTER to pointer-level, compress FTP proxy, drop spamd/greylisting

Diff Detail

Repository
R9 FreeBSD doc repository
Lint
Lint Skipped
Unit
Tests Skipped

Event Timeline

carlavilla created this revision.

Unfortunately, there is very little I can contribute here. My knowledge in regards of all of these FWs is close to zero.

documentation/content/en/books/handbook/firewalls/_index.adoc
871

Though I am not a native speaker, shouldn't it be "which does not require a custom kernel"? Hope a native speak can clarify because the sentence reads awkwardly for me.

carlavilla marked an inline comment as done.
carlavilla added reviewers: emaste, philip, lwhsu, bofh, dbaio, ebrandi.

This is really difficult to review. I wonder if it wants to be several smaller commits instead of one huge one.

An initial observation: do we simply want to get rid of all mentions of FTP? It looks like that's what's happening. Splitting that out into a single commit would already make the rest easier to review.