Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 26 Jan 2006 16:22:54 -0800 (PST)
From:      gahn <ipfreak@yahoo.com>
To:        Arne Woerner <arne_woerner@yahoo.com>, freebsd security <freebsd-security@freebsd.org>, freebsd general questions <freebsd-questions@freebsd.org>
Subject:   Re: strange problem with ipfw and rc.conf
Message-ID:  <20060127002255.61680.qmail@web52104.mail.yahoo.com>
In-Reply-To: <20060127000331.24566.qmail@web30307.mail.mud.yahoo.com>

next in thread | previous in thread | raw e-mail | index | archive | help
Thanks.

I don't think it was the problem of ipfw rulesets. In
fact once I did "sh /etc/ipfw.rules" and things are
fine. I just cant figure out why the rc.conf won't
load the rulesets.

Besides, I recompiled the customized kernel and there
is no need for "firewall_enable="YES"" statement in
rc.conf. 



--- Arne Woerner <arne_woerner@yahoo.com> wrote:

> --- gahn <ipfreak@yahoo.com> wrote:
> > 65335 locking out everything). I have to do "sh
> > /etc/ipfw.rules" in order to load the rulesets,
> once I
> > did that, I can access the box from remote
> locations
> > 
> Hmm...
> 
> It helped me, to look at /etc/rc.firewall... There
> are some
> comments, that might give u the right hints...
> 
> Maybe firewall_enable should be YES?
> 
> E. g. my /etc/rc.firewall.bartely file cannot be
> executed with
> sh... But maybe I still did not understand ipfw...
> 
> My /etc/rc.firewall.bartely contains rules like:
> add pass log all from any to 47.11.42.42
> add deny log all from any to any
> 
> And in rc.conf my
> firewall_type=/etc/rc.firewall.bartleby
> 
> And I use default firewall_script=/etc/rc.firewall
> 
> -Arne
> 
> 
> __________________________________________________
> Do You Yahoo!?
> Tired of spam?  Yahoo! Mail has the best spam
> protection around 
> http://mail.yahoo.com 
> 


__________________________________________________
Do You Yahoo!?
Tired of spam?  Yahoo! Mail has the best spam protection around 
http://mail.yahoo.com 



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20060127002255.61680.qmail>