
The Book of PF, 4th Edition
A No-Nonsense Guide to the OpenBSD Firewall
Peter N.M. Hansteen(Author)
No Starch Press
Published on 10. March 2026
Book
Paperback/Softback
264 pages
978-1-7185-0470-7 (ISBN)
Description
The OpenBSD packet filter, PF, is central to the OpenBSD and FreeBSD network toolbox. With more and more services placing high demands on bandwidth and an increasingly hostile Internet environment, no sysadmin can afford to be without PF expertise. The fourth edition of The Book of PF covers the most up-to-date developments in PF, including new content on IPv6, dual stack configurations, the 'queues and priorities' traffic-shaping system, NAT and redirection, wireless networking, spam fighting, failover provisioning, logging, and more. You'll also learn how to: Create rule sets for all kinds of network traffic, IPv4 and IPv6 both, whether crossing a simple LAN, hiding behind NAT, traversing DMZs, or spanning bridges or wider networks. Set up wireless networks with access points, and lock them down using authpf and special access restrictions. Maximize flexibility and service availability via CARP, relayd, and redirection. Build adaptive firewalls to proactively defend against attackers and spammers. Harness OpenBSD's latest traffic-shaping system to keep your network responsive, or use ALTQ and Dummynet configurations on FreeBSD to full effect. Stay in control of your traffic with monitoring and visualization tools (including NetFlow). The Book of PF is the essential guide to building a secure network with PF. With a little effort and this book, you'll be well prepared to unlock PF's full potential. Covers OpenBSD 7.6 and FreeBSD 14.x.
More details
Language
English
Place of publication
San Francisco
United States
Product notice
Paperback (trade)
Dimensions
Height: 235 mm
Width: 180 mm
Thickness: 22 mm
Weight
502 gr
ISBN-13
978-1-7185-0470-7 (9781718504707)
Copyright in bibliographic data and cover images is held by Nielsen Book Services Limited or by the publishers or by their respective licensors: all rights reserved.
Schweitzer Classification
Other editions
Additional editions

E-Book
03/2026
No Starch Press
€46.99
Available for download
Person
Peter N. M. Hansteen is a DevOps (formerly sysadmin) consultant and writer based in Bergen, Norway. A longtime Freenix advocate, Hansteen is a frequent lecturer on OpenBSD and FreeBSD topics. He also occasionally contributes articles to websites and magazines, and blogs on mainly networking related topics at That Grumpy BSD Guy. Hansteen was a participant in the original RFC 1149 implementation team. The Book of PF is an expanded follow-up to his very popular online PF tutorial.
Content
Foreword to the First Edition
Acknowledgments
Introduction
Chapter 1: Building the Network You Need
Chapter 2: PF Configuration Basics
Chapter 3: Into the Real World
Chapter 4: Wireless Networks Made Easy
Chapter 5: Bigger or Trickier Networks
Chapter 6: Turning the Tables for Proactive Defense
Chapter 7: Traffic Shaping with Queues and Priorities
Chapter 8: Redundancy and Resource Availability
Chapter 9: Logging, Monitoring, and Statistics
Chapter 10: Getting Your Setup Just Right
Appendix A: Resources
Appendix B: A Note on Hardware Support
Index
Acknowledgments
Introduction
Chapter 1: Building the Network You Need
Chapter 2: PF Configuration Basics
Chapter 3: Into the Real World
Chapter 4: Wireless Networks Made Easy
Chapter 5: Bigger or Trickier Networks
Chapter 6: Turning the Tables for Proactive Defense
Chapter 7: Traffic Shaping with Queues and Priorities
Chapter 8: Redundancy and Resource Availability
Chapter 9: Logging, Monitoring, and Statistics
Chapter 10: Getting Your Setup Just Right
Appendix A: Resources
Appendix B: A Note on Hardware Support
Index