Todo #5508
closed
Added by Chris Buechler about 9 years ago.
Updated almost 9 years ago.
Description
ipfw-classifyd and friends haven't worked correctly in any FreeBSD 10.x base version, the functionality as implemented had extremely high CPU overhead and other difficulties back when it did (sort of) work, and it was very rarely used.
Opening this todo in favor of #4276 / #4416 / #4993
- Status changed from Assigned to Feedback
- Description updated (diff)
Do you mean that Layer7 will disappear form the base distro?
Regards
Florent THOMAS wrote:
Do you mean that Layer7 will disappear form the base distro?
Regards
Considering it's been completely broken ever since 2.2, what's the big surprise here?
PR https://github.com/pfsense/pfsense/pull/2104 to remove a little bit more dead code.
Does anything need to be done to upgrade configs? Rules that have layer7 stuff might suddenly become [more|differently] permissive when the matched packets are no longer diverted to layer7 processing?
Kill Bill wrote:
Considering it's been completely broken ever since 2.2, what's the big surprise here?
Well, my question was more to know if there is an alternative planned? Applicative filter is a great solution and seeing it disappears from my favorite network distro is a sad news ;-)
Not that much of a loss. It never worked well anyhow. The pattern files from the upstream project were out of date and unmaintained, and they rarely matched things properly.
Keep an eye on snort with OpenAppID if you're wanting to block.
- Status changed from Feedback to Resolved
config upgrade code added to remove any layer7 configuration, and file a notice where found so users are clearly aware. Verified that's all fine with multiple diff configs.
That was the last piece of this.
Also available in: Atom
PDF