Subject: Re: NetBSD addict
To: NetBSD mailing list <nbsd@righi.df.unibo.it>
From: Mipam <mipam@ibb.net>
List: netbsd-help
Date: 12/21/2000 12:23:33
On Thu, Dec 21, 2000 at 10:11:58AM +0100, NetBSD mailing list wrote:
> 
> Hello ppl I tryed FreeBSD OpenBSD and NetBSD over the years.
> I like better NetBSD.
> But I have to convince my boss it is better than the others in using it as
> IPfilter firewall system.
> Does NetBSD has bridge option between NIC interfaces ??

1.4.x dont, also 1.5 does not, but i aint sure in the case of 1.5

> Does NetBSD has a more recent version of IPfilter running on it than than
> the other 2 BSD systems ??

Nope, but is that really needed? More current doesnt always mean
more stable, less bugs, more secure etc. Ipf needs to be stable and work 
correctly, that's what it does with the version implemented in NetBSD.
If you really wish to run a very current release, then you can also
download it, build it, patch the kernel src, build a new kernel, reboot and
you're on.

> Can I use IPfilter  in NEtBSD filtering packets between the 2  bridged
> interfaces?

If bridging would be implemented it would be possible.
For now, nope. I also thought i really wanted to use a bridge construction
sometimes. But found always a way around it. And if you wish it for security
and integrity of your firewall machine, you could also consider
disabling all services listening to the outside world, so there wont be
any open ports listening. Only way to configure it then would be
from the console.
Bye,

Mipam.