Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't have good examples of what can or cannot be done.

But I find pf much easier to understand. I can write pf rules myself and understand, clearly, what my firewall is doing. I haven't found iptables near as approachable, and depend on firewall configuration tools to generate the rules and chains for me.



I'd definitely agree that iptables is not nearly as approachable as i've seen pf be. I've yet to see something that can't be done with it if you take the time (this is discounting performance, i know that it can get a little hairy after a few hundred rules if not setup correctly).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: