b52d PF Changes with 9.0 - The FreeBSD Forums
The FreeBSD Forums  

Go Back   The FreeBSD Forums > Server & Networking > Firewalls

Firewalls IPFW, PF, IPF (but not limited) related discussion

Reply
 
Thread Tools Display Modes
  #1  
Old May 2nd, 2012, 20:56
jnbek's Avatar
jnbek jnbek is offline
Junior Member
 
Join Date: Jan 2010
Location: Wasatch Front, Utah
Posts: 93
Thanks: 22
Thanked 9 Times in 9 Posts
Default PF Changes with 9.0

Hey y'all,

I have a router/firewall built with PF, been using the same config setup since v5.3-RELEASE days, with great success. I am currently running 8.1 on the router and am considering making the jump to the 9 series, but I've seen loads of posts here titled PF and 9.0 problems, and I've come to understand that the pf.conf syntax has changed. Is there a migration utility, How-To or a resource that I can reference before doing the upgrade, so I can keep downtime to as long as it takes the machine to reboot into 9.0? What other gotchas should I look for with the jump from 8.1 -> 9.0? I will be using csup/make world method of upgrading, since I've had great success and have done this method from the above mentioned 5.3 to 8.1 with a slight bit of heartache going to the 7 series that was easily overcome, but I want to be prepared beforehand so I can just state all the more how awesome FreeBSD is �e�e
__________________
If you can not able use Perl for answer, you are ask wrong question.

Last edited by DutchDaemon; May 3rd, 2012 at 00:13.
Reply With Quote
  #2  
Old May 2nd, 2012, 21:08
kpa kpa is online now
Senior Member
 
Join Date: Jul 2010
Location: People's Technocratic Republic of Finland
Posts: 1,992
Thanks: 44
Thanked 460 Times in 390 Posts
Default

The syntax hasn't changed at all, the pf(4) implementation in FreeBSD 9.0 comes from OpenBSD 4.5 that is the last version with the old syntax. Newer versions of PF in OpenBSD have the newer syntax as documented by the PF FAQ at http://www.openbsd.org/faq/pf/
Reply With Quote
  #3  
Old May 2nd, 2012, 21:53
jnbek's Avatar
jnbek jnbek is offline
Junior Member
 
Join Date: Jan 2010
Location: Wasatch Front, Utah
Posts: 93
Thanks: 22
Thanked 9 Times in 9 Posts
Default

Sweet, did they offer a migration script or something?
__________________
If you can not able use Perl for answer, you are ask wrong question.
Reply With Quote
  #4  
Old May 3rd, 2012, 07:36
suntzu suntzu is offline
Junior Member
 
Join Date: Mar 2011
Posts: 21
Thanks: 0
Thanked 2 Times in 2 Posts
Default

No. You have to read the release notes and change your firewall configuration by yourself.
__________________
Tenim un nom, el sap tothom: FreeBSD

Last edited by DutchDaemon; May 3rd, 2012 at 12:11.
Reply With Quote
  #5  
Old July 7th, 2012, 23:10
Adrculda Adrculda is offline
Junior Member
 
Join Date: Feb 2012
Posts: 16
Thanks: 0
Thanked 0 Times in 0 Posts
Default

Let me know how it works out for you.
I'm running the new 2.1Beta but want Infiniband support which v8.3 doesn't offer...

Nevermind... thought you meant PFSense...

Last edited by Adrculda; July 20th, 2012 at 05:51.
Reply With Quote
Reply

Tags
9.0-release, advocacy, pf, upgrade

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 17:32.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.
The mark FreeBSD is a registered trademark of The FreeBSD Foundation and is used by The FreeBSD Project with the permission of The FreeBSD Foundation.
Web protection and acceleration provided by CloudFlare
0