Re: Diskless Success...Almost



Vladimir Tserijemiwtz <vladimir.tserijemiwtz@xxxxxxxxxxx> wrote:
problem. When I load ipfw, the default is set to deny all...that's good and
it's the way I want it. But of course the first thing that happens is it

Maybe because you told the module to do so?

denies all and because I'm using nfs it cannot run the fwrules set I have
ready. I guess I could recompile the kernel to allow everything, but that

Yes.
options IPFIREWALL_DEFAULT_TO_ACCEPT #allow everything by default

kind of defeats my purpose of the firewall being a very strict entry point
which denies everything unless specifically allowed.

Make a "last" rule with a "default deny" (one in front of the 65535 of the
system):

65534 deny ip from any to any

HTH
Clemens.
--
/"\ http://czauner.onlineloop.com/
\ / ASCII RIBBON CAMPAIGN
X AGAINST HTML MAIL
/ \ AND POSTINGS
.



Relevant Pages

  • Re: ISS Orbit Raising Burn Fails
    ... Noch nicht. ... \ / ASCII RIBBON CAMPAIGN ... X AGAINST HTML MAIL ... / \ AND POSTINGS ...
    (de.sci.raumfahrt)
  • Re: ist es denkbar ?
    ... \ / ASCII RIBBON CAMPAIGN ... X AGAINST HTML MAIL ... / \ AND POSTINGS ... Prev by Date: ...
    (de.sci.raumfahrt)
  • Re: Disk duplicate
    ... If you have a tape/cdr drive, take a look at MondoRescue. ... \ / ASCII RIBBON CAMPAIGN ... X AGAINST HTML MAIL ... / \ AND POSTINGS ...
    (Debian-User)
  • Re: Any decent PCI-E video card for xorg 7.3+
    ... they will *not* work with AMD64. ... \ / ASCII RIBBON CAMPAIGN ... X AGAINST HTML MAIL ... / \ AND POSTINGS ...
    (comp.unix.bsd.freebsd.misc)
  • Re: load of cpu
    ... e.g by following the sample-code in "man 3 sysctl". ... \ / ASCII RIBBON CAMPAIGN ... X AGAINST HTML MAIL ... / \ AND POSTINGS ...
    (comp.unix.bsd.freebsd.misc)