-
danmcd
ping
-
danmcd
(probably works... new switch who dis?)
-
Woodstock
pong
-
m1ari
pong
-
tsoome_
.oO kaboom!:)
-
SarahMalik
sal danmcd
-
danmcd
Bits are moving on the Kebecloud/danmcd-at-work networks. (For the Triton-aware, Kebecloud's "external" network is my HDC's "work" network.)
-
sommerfeld
danmcd: out of curiosity, what's your new switch?
-
danmcd
-
tsoome_
looks really nice.
-
gitomat
[illumos-gate] 14733 loader.efi: faults could try to print out call trace -- Toomas Soome <tsoome⊙mc>
-
szilard
I had a discussion with Alan Coopersmith on MAstodon. He is a Solaris developer at Oracle. I asked him regarding open sourcing the PF Solaris port. He contacted me, the next source drop will include the open source part of PF. It means they keep some interfacing logic between PF and the kernel closed source, but that can be recreated.
-
szilard
It means it could be somewhat easier to get a modern firewall for Illumos
-
richlowe
the kernel part of pf is the hard part
-
richlowe
unfortunately.
-
danmcd
Also, is pf like ipf in that it's FW *and* NAT? I think we can Do Really Better in NAT-land. I know OPTE exists in Oxide, but that feels too heavyweight.
-
danmcd
We have conn_t that can be repurposed for NAT session state (where the conn_t points to the "external network(s)" side).
-
richlowe
danmcd: this is all artifacts of porting the kernel side
-
richlowe
and yeah, the harder part
-
szilard
this is well beyond me, I just know PF from using OpenBSD on desktop, so not mission-critical setting. I tought it could be still useful to get the adapted PF sources from Oracle
-
richlowe
oh, it no doubt is!
-
richlowe
I just was just trying to temper anyones hopes
-
richlowe
(I wish for pf too, I just don't have the time to build the expertise)
-
richlowe
I think anyone who has seen ipf on the inside is at least very open to the idea
-
jbk
heh
-
szilard
I haven't seen ipf inside out, but i have spendt countless hours to try to secure my NAS from the aliens. What I noticed it is pretty similar to PF on the rule-level.
-
szilard
It took around 2 months for the Oracle guys to give a positive feedback, so in case you want something from Oracle but you were to shy to ask: just do it.
-
szilard
-
alanc
it'll be a few weeks still until the 11.4.90 release with those source files in (and a few others added too)
-
alanc
amusingly the one source file in that release with a Joyent copyright & CDDL license came to us from FreeBSD, not illumos
-
szilard
I didn't noticed you are here :)
-
szilard
Nice to meet you Alan.
-
szilard
And also good night, it is late now here. Bye!
-
gemelen
hm, that's interesting at least from the point of view that pf has better documentation than ipf