Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 17 Mar 2005 15:29:40 +0000 (UTC)
From:      Jeff Penn <jeff+list.news@jrpenn.demon.co.uk>
To:        freebsd-questions@freebsd.org
Subject:   Re: pf seems to start late?
Message-ID:  <slrnd3djq0.ni.jeff%2Blist.news@jrpenn.demon.co.uk>
References:  <6.2.0.14.2.20050304062626.00aa8468@localhost> <20050304164136.GA1684@orion.daedalusnetworks.priv> <20050304173041.GA1314@orion.daedalusnetworks.priv> <d0mn3o$jkl$1@sea.gmane.org>

next in thread | previous in thread | raw e-mail | index | archive | help
Volodymyr Kostyrko <arcade@ints.net>:
>>>>Shouldn't PF start right after the interfaces come up? [...]
>
>    Guys, didn't you forgot that pf sometimes uses resolver to lookup 
> hostnames present in pf.conf? What happens if it should resole hostnames 
> with local named?

I noticed that openbsd does a two-stage startup if pf is enabled.
Rc initially defines rules for lo0, & ssh/dns/icmp/ etc from any
to any (also NFS if enabled).  After the network is started these rules
are replaced by loading pf.conf.

Jeff



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?slrnd3djq0.ni.jeff%2Blist.news>