[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Is a 'PF default to block' setting outside pf.conf a desirablefeature?



Jon Hart <[email protected]> writes:
> Unless I'm being completely mislead, this feature is already in place
> with OpenBSD.  See /etc/rc.  
Now that you mention it, it does look like the good people who ported PF
over to FreeBSD did not bring with them all of the PF related bits from
OpenBSD's /etc/rc.  The minimal default rule set AFAICS is the smart
solution to the problem.
-- 
Peter N. M. Hansteen, member of the first RFC 1149 implementation team
http://www.blug.linux.no/rfc1149/ http://www.datadok.no/ http://www.nuug.no/
"First, we kill all the spammers" The Usenet Bard, "Twice-forwarded tales"