Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> The firewall on OpenBSD is miles better to configure than iptables.

That's understating the matter by a huge amount.

pf is easier to read and understand, easier to adjust, more dynamic, and works like every other firewall in the world not based on iptables.



Seems a bit subjective. I find iptables much easier to work with.

But then again I've not run iptables for years. nftables has many benefits.


iptables is indeed horrid, but Linux has nftables nowadays, which is much nicer and easier to configure.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: