OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: pf firewall question

From: Lars Hansson (larsunet.net.ph)
Date: Mon May 01 2006 - 21:45:28 CDT


On Tuesday 02 May 2006 05:31, bofh wrote:

> I must say though, a well designed gui can be a great help in managing a
> set of firewalls, or a firewall with complex rules. I like pf for the
> cleanliness of syntax and simplicity of doing things, but the guy who ran
> the checkpoint firewalls for 50+ sets of firewalls and 2000+ rules across
> them all told me he would not have been able to manage it with pf, I did
> not believe him. Now that I'm managing a small bunch of checkpoint boxes
> with a few hundred rules, and some vpns, it *does* make things easier.

Maybe that says more about the design of Checkpoint than it does about pf.

---
Lars Hansson