From owner-freebsd-questions@FreeBSD.ORG Tue Sep 28 21:33:44 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 15E1C16A4CE for ; Tue, 28 Sep 2004 21:33:44 +0000 (GMT) Received: from mx2.magma.ca (mx2.magma.ca [206.191.0.250]) by mx1.FreeBSD.org (Postfix) with ESMTP id 8F22443D49 for ; Tue, 28 Sep 2004 21:33:43 +0000 (GMT) (envelope-from ebudd@grokking.org) Received: from in2.magma.ca (in2.magma.ca [206.191.0.224]) by mx2.magma.ca (8.13.0/8.13.0) with ESMTP id i8SLXfeh024166 for ; Tue, 28 Sep 2004 17:33:42 -0400 Received: from mx1.sohotech.ca (ottawa-hs-64-26-169-251.s-ip.magma.ca [64.26.169.251]) by in2.magma.ca (Magma's Mail Server) with ESMTP id i8SLWHsV013424 for ; Tue, 28 Sep 2004 17:32:36 -0400 Received: from heinlein.sohotech.ca (heinlein.sohotech.ca [192.168.1.3]) (authenticated bits=0) by mx1.sohotech.ca (8.12.10/8.12.10) with ESMTP id i8SLWH4C037783 for ; Tue, 28 Sep 2004 17:32:17 -0400 (EDT) (envelope-from ebudd@grokking.org) Date: Tue, 28 Sep 2004 17:32:17 -0400 From: Ed Budd To: freebsd-questions@freebsd.org Message-Id: <20040928173217.501889d6.ebudd@grokking.org> In-Reply-To: <415918AA.C4433D9D@sbhost.ro> References: <415918AA.C4433D9D@sbhost.ro> X-Mailer: Sylpheed version 0.9.12 (GTK+ 1.2.10; i686-pc-linux-gnu) Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit X-Scanned-By: MIMEDefang 2.44 Subject: Re: pf for FreeBSD X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 28 Sep 2004 21:33:44 -0000 On Tue, 28 Sep 2004 09:54:18 +0200 Cristi Tauber wrote: > hello folks, > i want to install the packet filter for FreeBSD so i recompile the > kernel with the options : > > device bpf > options PFIL_HOOKS > options RANDOM_IP_ID > > and installed pf from ports ( i did a cvsup before installing to > get the latest ports). Now my dilemma is ... in pf start script ... i > have to enter a prefix ... but what prefix, 'cause after installing > and rebooting .... the modules that I want to load are still in source > directory . I installed pf with Does the prefix by chance refer to the full path to the script (i.e. /usr/local/etc/rc.d/pf.sh)? Read the comments in the script; it will tell you what you need to do to /etc/rc.conf to get things started on bootup. > > make WITH_ALTQ=yes > make install I've been running pf on two separate FBSD 5.2.1 boxes for weeks without adding this switch. Only thing that doesn't work that great is spamd logging but otherwise I prefer pf over ipf and ipfw any day -- even on a ported OS... Cheers, EB