Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 10 Feb 2007 16:05:44 -0500
From:      "Dan Langille" <dan@langille.org>
To:        freebsd-pf@freebsd.org
Subject:   pf starts, but no rules
Message-ID:  <45CDED58.2056.1A642A00@dan.langille.org>

next in thread | raw e-mail | index | archive | help
Hi folks,

Yesterday I rebooted a server to load a new kernel.  After the 
reboot, the firewall rules were not loaded.

$ grep pf /etc/rc.conf
pf_enable="YES"
pflog_enable="YES"
pf_rules="/etc/pf.rules"

I never checked for the rules until today and found this:



[dan@nyi:~] $ sudo pfctl -sa | less
Password:
No ALTQ support in kernel
ALTQ related functions disabled
FILTER RULES:

INFO:
Status: Enabled for 0 days 19:59:39             Debug: None

Hostid: 0x36eae8cf

State Table                          Total             Rate
  current entries                        0
  searches                         5515422           76.6/s

etc...

Loading the rules manually works:

[dan@nyi:~] $ sudo pfctl -f /etc/pf.rules
No ALTQ support in kernel
ALTQ related functions disabled
[dan@nyi:~] $

After loading, pfctl -sa shows the output I would expect.

Ideas?  Suggestions?

Is anyone else using PF with a pf_rules specified?

FWIW, I notice I have one host identified by FQDN in my rules.

-- 
Dan Langille : Software Developer looking for work
my resume: http://www.freebsddiary.org/dan_langille.php
PGCon - The PostgreSQL Conference - http://www.pgcon.org/





Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?45CDED58.2056.1A642A00>