Networking Forums

Networking Forums > Computer Networking > Linux Networking > pf vs ipf vs iptables

Reply
Thread Tools Display Modes

pf vs ipf vs iptables

 
 
Ghazan Haider
Guest
Posts: n/a

 
      11-16-2003, 06:02 AM
Hi,
I'm a heavy Linux user and implementor at work, but due to chance I've
had more experience using packet filters on OpenBSD, Solaris and
FreeBSD. I've had most of my experience with pf on OpenBSD and
therefore its my favorite of the three, but I know iptables/netfilter
on Linux is more featureful. Linux has other advantages like a huge
number of ports, the biggest driver library of them all and very
cutting edge optimisations everywhere, not to mention more eyeballs at
work on the code.

So can people with experience please offer their biased and unbiased
opinions on these three ways of filtering TCPIP (v4 and v6) and IPX?
We're all most interested in ipv4 I guess.

On a related issue, does anyone know of the differences in benchmarks,
stability and methods of remembering states of level4 data that are
maintained in the memory? OpenBSD and Linux have seemed very stable
and fast, as packet filtering isnt quite a novelty, but with ipf in
Solaris and iptables in Linux kernel 2.4, I HAVE experienced slowdowns
when a great deal of connections are made, as in three different
workstations pinging a list of counterstrike servers (over 30 thousand
servers) simultaneously, and therefore exceeding 65535 connections
through a packet filtering firewall. This might well be a limit of
TCPIP itself where TCP ports are limited, but I need opinions on its
usability in high performance areas.
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
about iptables junaidaslam Linux Networking 3 08-29-2005 09:35 PM
Looking for iptables applications code (iptables.c) to run some rules to forward packets tvnaidu@yahoo.com Linux Networking 2 01-17-2005 05:01 PM
iptables Bernd Roth Linux Networking 5 01-16-2005 05:53 PM
iptables and nat Marcin Giedz Linux Networking 5 07-06-2004 07:05 AM
iptables "can't initialize iptables table `filter'" pete Linux Networking 1 10-10-2003 03:44 AM



1 2 3 4 5 6 7 8 9 10 11