https://en.wikipedia.org/wiki/Pfsync
Looks pretty cool. Had no idea this existed, but glad to hear about it.
https://en.wikipedia.org/wiki/Pfsync
Looks pretty cool. Had no idea this existed, but glad to hear about it.
OpenBSD's PF firewall has been adopted by Solaris, and I believe it is an option in FreeBSD and Linux.
For fun I've been monkeying around with a friendly pf library in everyone's favorite language, and the differences between bit me a few times… although it looks like FreeBSD-current is starting to work towards convergence. It's a really powerful tool, it'll let you write rules conditional on an OS fingerprint, handle a bunch of traffic normalization… but it's also been a reminder about how much I dislike C APIs (obviously most folks are going to be using pfctl which is just fine and dandy).
It's been a feature of pfsense for many years (the smart kids have moved onto opensense now though)
Sadly OPNsense is just another highly opinionated mess, just like pfSense now. The are things what are done better in OPNsense but overall the UI is worse than atrocious.
I'm trying to use it for more than 3 years, but as soon as I need something more than a very basic ruleset - things go south.
The lack of necessities (eg pre-populated RFC1918 networks in the aliases, or extreamly common things, like AD ports list) or a 'session' view which defaults to seven states in OPNsense is just an icing on the top.
ADD: forgot, those stupid CSS animations in OPN. Not only they are stupid and slow, I'm almost never access the WebGUI directly, so I'm forced to watch every frame to be sent on the net.
It's like they are never ever dogfooding their own products, except their local, small labs.
ADD2: I hated ISA Server with a passion, for it being an overcomplicated mess. But 20 years later I would gave my month supply of pumpkin latte to just have an easy way to work with network groups and high level network abstractions.
https://github.com/freebsd/freebsd-src/commits/main/sys/netp...
Does OPNsense?
https://old.reddit.com/r/homelab/comments/ssk8zj/til_in_2017...
We use pf+pfsync+carp extensively over in FreeBSD.org as well. It's good stuff!