[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Is a 'PF default to block' setting outside pf.conf a desirablefeature?

Damien Miller <[email protected]> writes:
> And the important thing to note is that this ruleset is applied before
> any interfaces are activated. No active interfaces == no packets
> making it to the kernel.
Yes, my point exactly.  I probably did not write it that well, since OP
went off complaining, though.
Peter N. M. Hansteen, member of the first RFC 1149 implementation team
http://www.blug.linux.no/rfc1149/ http://www.datadok.no/ http://www.nuug.no/
"First, we kill all the spammers" The Usenet Bard, "Twice-forwarded tales"