Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 6 Feb 2005 23:13:52 -0800
From:      Kris Kennaway <kris@obsecurity.org>
To:        Jim Arnold <jim0266@yahoo.com>
Cc:        freebsd-questions@freebsd.org
Subject:   Re: IP Filter changes in FreeBSD
Message-ID:  <20050207071352.GA4807@xor.obsecurity.org>
In-Reply-To: <a06210207be2caabf7209@[192.168.0.4]>
References:  <a06210207be2caabf7209@[192.168.0.4]>

next in thread | previous in thread | raw e-mail | index | archive | help

--X1bOJ3K7DJ5YkBrT
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Mon, Feb 07, 2005 at 12:24:09AM -0500, Jim Arnold wrote:
> I updated my firewall that is using IPF. I went from FreeBSD 4.7=20
> stable to 4.11 stable. When using 4.7 stable I only had this is my=20
> rc.conf file:
>=20
> ipfilter_enable=3D"YES"
> ipfilter_program=3D"/sbin/ipf"
> ipfilter_rules=3D"/etc/ipf.conf"
> ipfilter_flags=3D""
>=20
> When I went to 4.11 stable I had to uncomment these options in my=20
> kernel config file:
>=20
> options         IPFILTER
> options         IPFILTER_LOG
>=20
> I'm just curious why it worked without the above options in my kernel=20
> for 4.7 and I had to have them in 4.11?

If you don't have it in your kernel, the module will be loaded at boot
time if it's available.  If you don't have the module either, you
can't use ipfilter.

Kris


--X1bOJ3K7DJ5YkBrT
Content-Type: application/pgp-signature
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.0 (FreeBSD)

iD8DBQFCBxUwWry0BWjoQKURAoIlAJwNAvc6LkRfcLL0HWEuLb2F38MzSQCg/hqk
z68JOEkEa3jVqYQEEbQ76DQ=
=FqS7
-----END PGP SIGNATURE-----

--X1bOJ3K7DJ5YkBrT--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20050207071352.GA4807>