Re: alternatives to m0n0

Thomas Sprinzing <[email protected]> Thu, 19 Feb 2015 14:28:24 +0100
Newsgroups gmane.comp.security.firewalls.m0n0wall
Message-ID <[email protected]>
Lee,

just goes to show / guess we'll have to see an update in pf et al. soon:

https://lists.freebsd.org/pipermail/freebsd-current/2015-February/054580.html

We will have to get used to stuff like this, unfortunately things get 
borked all the faster nowadays.


Am 18.02.2015 um 18:06 schrieb [email protected]:
>> Given that, security-wise, the threat model for such devices and the speed
>> of discovery-release-exploit has developed to the worse lately, it makes
>> much more sense in my opinion to put the collective effort into a project
>> which is based on current base packages rather than keeping the old thing
>> afloat. Especially so, when your time and expertise is limited.
>
> Funny that you should bring this up...  When Heartbleed came out, pfSense
> needed a new build.  When Shellshocked came out, pfSense and nas4free both
> needed new builds.  m0n0wall did not.  Lean systems have less attack
> vectors.  And with OpenSense being 64bit dual core, all of the rather nice
> Atom platforms are off the table.
>
> I am not advocating a vintage firewall.  I am advocating a LEAN firewall.
>
> Lee
>
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>