#FreeBSD #HotTake: Even though everyone with deeper #firewall juju than myself says #pf is better than #ipfw, so I guess it must be, I still like knowing my rules by numbers that don’t change. Plus I have tools written over many years around ipfw and would need to totally redesign them conceptually for pf. I don't have enough working years to do that.

#Sysadminnery

@grumpybozo i don't mind ipfw, but one reason i prefer pf is that ipfw can't do IPv6 fragment reassembly, which makes it rather useless as a stateful firewall...
@lw Neither my own ISP nor my employer are handling IPv6 yet, so that’s non-critical for me, but it is good to keep in mind if my networking guys ever aren’t swamped and actually deploy our vast allocation of IPv6 space.