Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 29 Mar 2000 10:31:24 -0600 (CST)
From:      Brennan W Stehling <brennan@offwhite.net>
To:        Richard Martin <dmartin@origen.com>
Cc:        Achim Patzner <ap@bnc.net>, freebsd-ipfw@FreeBSD.ORG
Subject:   Re: NATD Translation
Message-ID:  <Pine.BSF.4.10.10003291026370.72565-100000@home.offwhite.net>
In-Reply-To: <38E21E40.2FA2352A@origen.com>

next in thread | previous in thread | raw e-mail | index | archive | help
I have a correction to my last comment.

I looked up the rc.conf setting for firewall=open and I think you can
ignore it.  It appears that I actually am using the wrong variable name.
In the LINT kernel example config file you will find and explanation for
it.  Here is it.

# WARNING:  IPFIREWALL defaults to a policy of "deny ip from any to any"
# and if you do not add other rules during startup to allow access,
# YOU WILL LOCK YOURSELF OUT.  It is suggested that you set
firewall_type=open
# in /etc/rc.conf when first enabling this feature, then refining the
# firewall rules in /etc/rc.firewall after you've tested that the new 
kernel
# feature works properly.

I must have had a typo when setting this up but it still worked.  I was
just being cautious without any real good reason.  I am guessing that
/etc/rc.firewall set up the rules just right for me so that it would work.
Since it worked for me right away I did not spend any more time with it.

I am now trying to learn more about it now.

Brennan Stehling - web developer and sys admin
projects: www.onmilwaukee.com | www.sncalumni.com

fortune:
Eggheads unite!  You have nothing to lose but your yolks.
		-- Adlai Stevenson




To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-ipfw" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.10.10003291026370.72565-100000>