I'm late into this discussion, but I guess I'm glad that ipfilter will continue 
in FreeBSD....

It has only been since last summer that we've gotten our first production 
FreeBSD server.  Several of us in the sysadmin team have been behind the 
possibility to varying degrees.   We had pitched it an option to a federal site 
that we support, that was looking to replace their aging Solaris server. They 
had come to like ZFS and Zones in Solaris 10, but wanted to maximize 
performance and work within their declining IT budget, so going to FreeBSD with 
ZFS and jails seemed ideal.  One day it suddenly appeared....

I was able to get up to speed and quickly adapt most of our configuration 
management system (cfengine2) to support FreeBSD 9 (before this I had only used 
FreeBSD 2 -- ran a Free-Net.)  In the area of host based firewall, pretty much 
the only changes for FreeBSD was /usr/sbin/ipf vs /sbin/ipf and SMF vs 
/etc/rc.d.  Having to support another firewall in our configuration generation 
process would've been a problem (though it is in need of a rewrite, which it 
may get since its likely we'll be moving to chef in the near future.)

While personally, I would likely have adapted to using something else on my 
home system since I had played a little bit with ipfw and pf while 
investigating a performance problem of doing policy based routing to be able to 
have a jail with a different gateway.  Which was resolved by using FIBs.  And, 
I've been thinking of replacing my dd-wrt routers with pfsense....  And, I'm 
staying with cfengine3 for configuration management of my home systems, even 
though management has decided that we will go with chef ... because it might 
have some interesting features (and does things that requires purchasing the 
enterprise edition of cfengine3), though it doesn't do some of the processes 
that are critical to our current processes.

We're still using cfengine2 at work, though I've heard that getting server 
upgraded to cfengine3 is nearly done.  Though sounds like to get us on board, 
they'll send us to chef training....(or bring training on site)

_______________________________________________
freebsd-net@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-net
To unsubscribe, send any mail to "freebsd-net-unsubscr...@freebsd.org"

Reply via email to