Hacker news

  • Top
  • New
  • Past
  • Ask
  • Show
  • Jobs

pf: Make af-to less magical (https://undeadly.org)

52 points by defrost 3 days ago | 15 comments | View on ycombinator

rnhmjoj 3 days ago |

I didn't know BSD had an IPv4/IPv6 translation mechanism built-in. On Linux the state of the art seems to be Jool[1], which is unfortunately an out-of-tree kernel module. IIUC, they currently share the limitation of not being able to translate locally-originated packets, which can be annoying unless you have a machine to dedicate to the translation.

[1]: https://nicmx.github.io/Jool/en/intro-jool.html

user3939382 2 days ago |

The easiest change to make to pf is making BC breaks to everyone’s firewall config which OpenBSD has done multiple times. If you want to make ipv6 nice great. Please do not break users’ existing configs to do it. TDR is wrong and breaking BC for syntax sugar is not better for security it’s better for losing users.