[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Debian as My home firewall/router



On 02/27/2016 01:29 PM, Reco wrote:
On Sat, 27 Feb 2016 12:54:52 -0800
David Christensen <dpchrist@holgerdanske.com> wrote:

On 02/27/2016 10:40 AM, Reco wrote:

On Sat, 27 Feb 2016 09:41:47 -0800
David Christensen <dpchrist@holgerdanske.com> wrote:

3. What is your opinion of pfSense?

	https://pfsense.org/

I'm by no means an expert on FreeBSD (from which pfSense is derived) so
I suggest to search more educated evaluation elsewhere.

I ran pfSense briefly on the Internet connection for my SOHO LAN.  There
are differences between BSD vocabulary and Linux vocabulary, but
functionality is pretty much the same.  pfSense seemed more
sophisticated and featureful than IPCop, but more brittle.

Now you picked my curiosity. In what ways pfSense is "more brittle"?

The two things I remember are:

1. The pfSense installer wanted to use the whole disk. The only way I could get it to use only part of the disk was to create a slice for pfSense and create another slice that ate up all remaining free space. Then every time I booted, the boot loader (GRUB2, I believe) would show both slices, even though I don't recall setting the boot bit on the second slice.

2. I typically power down my machines every night. After a month or two of use, the pfSense box would not boot. I didn't, and still don't, know enough about BSD to figure out why. The first time or two, I wiped the HDD, reinstalled, and reconfigured. The last time it was behind another firewall, so I pulled the pfSense box.


I suspect that pfSense lacks any meaningful mandatory access control
pre-installed (no *BSD family has it), but that's it.

According to McKusick [1], p. 34, "FreeBSD implements a framework for
kernel access-control extensibility, the MAC framework".

So it's so called capiscum framework. A nice sandbox effort, but it's
nowhere near SELinux capabilities. A direct analogy from the Linux
world is seccomp.

If they use it in pfSense - that's good. The main question is - how
meaningful is the use of this framework pfSense has?

I need to finish McKusick's book and research if/ what/ how pfSense makes use of the BSD MAC framework.


David


Reply to: