I actually was reading a good document on PF tonight and I came across
this quote that I think would answer your question as to the difference
between iptables and pf.
OK, may be it's more poetic, but still I really liked it.
Hope it make you think as well! (:>
And I think it describe it very well if you have played with them!
Daniel
Quote:
Compared to working with iptables, PF is like this haiku:
A breath of fresh air,
floating on white rose petals,
eating strawberries.
Now Im getting carried away:
Hartmeier codes now,
Henning knows not why it fails,
fails only for n00b.
Tables load my lists,
tarpit for the asshole spammer,
death to his mail store.
CARP due to Cisco,
redundant blessed packets,
licensed free for me.
Jason Dixon, on the PF email list, May 20th, 2004
(http://www.benzedrine.cx/pf/msg04702.html)