pf-filter

  1. K

    PF Centralize PF for all the VMs on host machine, or separated PFs for each VM?

    Hello. I'm preparing to manage few VMs under FreeBSD bhyve, and focusing on implementing a good set of PF rules on the main host machine. I wanted to ask for your opinions, is it wise to have a rule like; pass in/out quick on vm-publicswitch all (vm-publicswitch containing all the IP ranges...
  2. Incnis Mrsi

    “Stateful” gotcha in pf(4)

    The NetBSD FAQ on pf states: Although it might be handy for firewalling proper, “passing without going through ruleset evaluation” is abysmally silly for routing. Yesterday Ī̲ found that my system of rules, based on the dual-homed-ipv6-via-freebsd-gateway-with-pf-4.82761, doesn’t work...
  3. Incnis Mrsi

    Solved Dual-homed IPv6 via FreeBSD gateway with pf(4)

    Hopefully my experience and analysis will be appreciated here. IPv6 was developed having multihoming in mind, and it can be beneficial when no single “good” IPv6 supply exists locally. In many parts of the world an ISP can linger in business without offering IPv6 connectivity. The shortage of...
Back
Top