Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 09 Dec 2003 21:31:23 -0800
From:      Michael Sierchio <kudzu@tenebras.com>
To:        Steve Bertrand <iaccounts@northnetworks.ca>
Cc:        freebsd-ipfw@freebsd.org
Subject:   Re: Safe IPFW ruleset
Message-ID:  <3FD6AFAB.6010505@tenebras.com>
In-Reply-To: <1071033684.25139.1.camel@ptp.northnetworks.ca>
References:  <1071033684.25139.1.camel@ptp.northnetworks.ca>

next in thread | previous in thread | raw e-mail | index | archive | help
Steve Bertrand wrote:
> Does anyone have a preferred method for a safe ipfw reload while a few
> hundred miles away from the server. I have tried a few, but would like
> some personal experiences.

Use IPFW2 and the atomic swapping of sets.

You may also add rules that get matched prior to
the current ruleset (in a different set) and diable
the original set when convenient.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3FD6AFAB.6010505>