4 ms·
why would you not just run OpenBSD with PF.
by jessebarton 6y ago
why would you not just run OpenBSD with PF.
- bpye 6y agoWhy should I choose OpenBSD over FreeBSD or even Linux with nftables?
- dijit 6y agoIf you’re really asking, and not making a point; PF is created and primarily maintained by OpenBSD OpenBSD’s base system (without extra packages) includes PF and has a focus on security. PF in freebsd is several major versions old. nftables (like iptables before it) is rule based and not bucket based. So high numbers of rules will not affect pf’s performance like it does with nftables. But, for home users, probably not noticeable. Though I prefer the syntax of PF personally.
- hyperpl 6y agoWireguard has also been stable on OpenBSD which helped me with my throughput on my apu2d router hardware.
- fuzzy2 6y agoCould you expand on what you mean by "bucket based"? Maybe the so-called "tables"? They sound pretty identical to ipset on Linux.
- dijit 6y agoHere's how a packet flows through netfilter[0], and here's how it flows through pf[1]. [0]: https://upload.wikimedia.org/wikipedia/commons/3/37/Netfilter-packet-flow.svg https://upload.wikimedia.org/wikipedia/commons/3/37/Netfilte... [1]: http://mailing.openbsd.misc.narkive.com/jtIB9W3w/pf-packet-flow-diagram:i.2.1.full http://mailing.openbsd.misc.narkive.com/jtIB9W3w/pf-packet-f...
- ta20210405 6y ago>nftables (like iptables before it) is rule based and not bucket based. What does this even mean? Do you have any documentation to explain? >So high numbers of rules will not affect pf’s performance like it does with nftables. This is wrong. From OpenBSD documentation: "More lines being evaluated for each packet will result in slower performance." [0]https://www.openbsd.org/faq/pf/perf.html https://www.openbsd.org/faq/pf/perf.html It's not 2001 any more. Nftables and Linux have left the BSDs in the dust.
- dijit 6y agoThe key is “for each packet”, because it’s bucket based it will entirely skip evaluation for packets that do not match. This is due to how the rule set is compiled, but I can see how it could be confusing if you’re used to iptables and only think in those terms. I posted the architectural diagrams of both in another comment on this thread yesterday, I think you missed that.
- ta20210405 6y ago>The key is “for each packet”, because it’s bucket based it will entirely skip evaluation for packets that do not match. That is how it works in nftables. >but I can see how it could be confusing if you’re used to iptables and only think in those terms. Considering you're misunderstanding some basics about nftables and iptables here, I think you need to look in the mirror. >I posted the architectural diagrams of both in another comment on this thread yesterday, I think you missed that. I saw, and it only reenforced the fact that that's how nftables works. Hilariously enough, the OpenBSD webpage crashed and wouldn't load, giving various 500 and 42X errors.
- deleted 6y ago[deleted]
- ta20210405 6y agoHere is an article that covers performance between Linux and FreeBSD, and it leaves BSD in the dust: https://matteocroce.medium.com/linux-and-freebsd-networking-cbadcdb15ddd https://matteocroce.medium.com/linux-and-freebsd-networking-... Also, it specifically outlined how more rules slow down of on FreeBSD, and how poor multicore support is on pf.
- hyperpl 6y agoI switched from pfsense + Ubiquiti to OpenBSD + Ruckus and couldn't be happier. While the web UIs were cool for a day, with the command line I feel as though I understand exactly what I have setup a bit better. Ruckus UI is also much more friendly than Ubiquiti's - I had to actually install mongo db + VM/dock just to configure my Ubiquiti WAP? Seriously? I just wish I had completely deleted my Ubiquiti account when I sold my WAP.
- ridiculous_fish 6y agoWhat hardware are you using?
- apple4ever 6y agoWhat Ruckus gear are you running? Last I looked it was pretty expensive.
- amluto 6y agoeBay. The secondary market for high-end network switches is excellent if you’re a buyer.
- apple4ever 6y agoYa I did some research and it's not bad at all. And ruckus is pretty good with their firmware options. In fact I'm buying two new R710s to replace my very old UAC AP Pros. Was going to get the new AP 6 LR but after UIs current woes (and them dropping support for my APs way too early) I'm done with them.
- wcfields 6y agoI ran into issues with firmware on a ZoneDirector 1200 and some R610's that were out of support contract. Totally functional and all, but couldn't bring them current. Though, After using Ruckus in Corp/Enterprise they've sold me on how capable their APs are, it's real deal high density stuff.
- posguy 6y agoDoes OpenBSD with PF have a nice web interface to administrate the firewall, DHCP server, WLANs, etc from?