Found a reason to leave ipfwadm and 2.0.38 kernel

datawolf@ibm.net datawolf@ibm.net
Sun, 18 Jun 2000 21:36:42 -0700


"J.L.Francois" wrote:
> 
> So, if you plan to have a high volume TCP/UDP gateway
> with lots of transient IP address traffic, I would
> suggest going straight to 2.2.16 and using ipfilter
> if you plan on using NAT/IP-MASQ.
> Although this is the PLUG list, any BSD is also an option.

THE ipfilter?  As in http://coombs.anu.edu.au/~avalon/ , which is
OpenBSD's default firewall software?

If so, their FAQ says:

Q. Has IP Filter been ported to or is anyone porting it to Linux ?

A. Yes. It has been ported, successfully to RedHat 4.2. It expected to
work reasonably well with any 2.0.31+ kernel, on a non-glibc system. It
does not work with any other later release of Linux. 

If you've gotten it to work under 2.2.x, please give some details.  If
you're talking about something else, please set me straight.

My firewall is now dual-boot Linux and OpenBSD.  If I could use the same
firewall rules for both, that would be cool.

-BVG