From owner-freebsd-questions@FreeBSD.ORG Tue May 24 15:21:36 2005 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 1BB7016A41C for ; Tue, 24 May 2005 15:21:36 +0000 (GMT) (envelope-from cswiger@mac.com) Received: from smtpout.mac.com (smtpout.mac.com [17.250.248.46]) by mx1.FreeBSD.org (Postfix) with ESMTP id DBFD643D1D for ; Tue, 24 May 2005 15:21:35 +0000 (GMT) (envelope-from cswiger@mac.com) Received: from mac.com (smtpin02-en2 [10.13.10.147]) by smtpout.mac.com (Xserve/8.12.11/smtpout10/MantshX 4.0) with ESMTP id j4OFLZWx004422; Tue, 24 May 2005 08:21:35 -0700 (PDT) Received: from [192.168.1.6] (pool-68-161-53-96.ny325.east.verizon.net [68.161.53.96]) (authenticated bits=0) by mac.com (Xserve/smtpin02/MantshX 4.0) with ESMTP id j4OFLV4L014773; Tue, 24 May 2005 08:21:33 -0700 (PDT) In-Reply-To: <51d7a516050524080843451d09@mail.gmail.com> References: <51d7a516050524080843451d09@mail.gmail.com> Mime-Version: 1.0 (Apple Message framework v730) Content-Type: text/plain; charset=US-ASCII; delsp=yes; format=flowed Message-Id: <4580439D-D489-4471-A026-4D8443B92C2D@mac.com> Content-Transfer-Encoding: 7bit From: Charles Swiger Date: Tue, 24 May 2005 11:21:25 -0400 To: perikillo X-Mailer: Apple Mail (2.730) Cc: freebsd-questions@freebsd.org Subject: Re: question about dhcp client X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 24 May 2005 15:21:36 -0000 On May 24, 2005, at 11:08 AM, perikillo wrote: > Hi all, iam going to setup one firewall for a friend, i need to > use the > dhcp client to get the IP, my question is: > > 1; I need to have the BPF device enable, is a rule? You need BPF if you want dhclient to work, yes. > Because normally, by security is recomend that this option need to be > disable!!! Agreed. Using dynamic network configuration on a firewall is not very secure. Get a broadband router to do DHCP and NAT, and place your firewall between that device and your network configured using static info... -- -Chuck