Skip site navigation (1)Skip section navigation (2)
Date:      06 Oct 2000 10:06:56 +0200
From:      Dag-Erling Smorgrav <des@ofug.org>
To:        Roman Shterenzon <roman@xpert.com>
Cc:        Craig Cowen <craig@allmaui.com>, freebsd-security@FreeBSD.ORG
Subject:   Re: Default Deny
Message-ID:  <xzpya02e6lb.fsf@flood.ping.uio.no>
In-Reply-To: Roman Shterenzon's message of "Fri, 6 Oct 2000 02:40:08 %2B0200 (IST)"
References:  <Pine.LNX.4.10.10010060238280.22615-100000@jamus.xpert.com>

next in thread | previous in thread | raw e-mail | index | archive | help
Roman Shterenzon <roman@xpert.com> writes:
> The ipfilter in freebsd seems cursed or abandoned.
> Example: this option is not documented.
> Another example: there're no hooks to start ipfilter from /etc/rc*
> eventhough there's PR: 20202

Put this in your rc.conf:

firewall_enable="YES"
firewall_script="/etc/firewall"

Where /etc/firewall is a shell script that sets up your firewall.

DES
-- 
Dag-Erling Smorgrav - des@ofug.org


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?xzpya02e6lb.fsf>