From owner-freebsd-questions@FreeBSD.ORG Fri Jan 27 00:03:33 2006 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 3560316A422 for ; Fri, 27 Jan 2006 00:03:33 +0000 (GMT) (envelope-from arne_woerner@yahoo.com) Received: from web30307.mail.mud.yahoo.com (web30307.mail.mud.yahoo.com [68.142.200.100]) by mx1.FreeBSD.org (Postfix) with SMTP id 59F4143D46 for ; Fri, 27 Jan 2006 00:03:32 +0000 (GMT) (envelope-from arne_woerner@yahoo.com) Received: (qmail 24568 invoked by uid 60001); 27 Jan 2006 00:03:31 -0000 DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.com; h=Message-ID:Received:Date:From:Subject:To:In-Reply-To:MIME-Version:Content-Type:Content-Transfer-Encoding; b=YLsHb1sY8drAlxRFCoUL+dhlwcOuBI1se2nagrXO90PSr1gDzs0Z0E7Tbskwm0jOmYxiPHtvz3WR2eF14fpEcH4V7vi0pC6pccaR9cq6qO97CCIfudj6iVOEKZFW1vC5J0QXoM5fgGvCSSmstJqc64AhQ6lMtAGuS9sjeJn9M2I= ; Message-ID: <20060127000331.24566.qmail@web30307.mail.mud.yahoo.com> Received: from [213.54.68.25] by web30307.mail.mud.yahoo.com via HTTP; Thu, 26 Jan 2006 16:03:31 PST Date: Thu, 26 Jan 2006 16:03:31 -0800 (PST) From: Arne Woerner To: gahn , freebsd security , freebsd general questions In-Reply-To: <20060126233439.62351.qmail@web52101.mail.yahoo.com> MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Transfer-Encoding: 8bit Cc: Subject: Re: strange problem with ipfw and rc.conf X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 27 Jan 2006 00:03:33 -0000 --- gahn wrote: > 65335 locking out everything). I have to do "sh > /etc/ipfw.rules" in order to load the rulesets, once I > did that, I can access the box from remote locations > Hmm... It helped me, to look at /etc/rc.firewall... There are some comments, that might give u the right hints... Maybe firewall_enable should be YES? E. g. my /etc/rc.firewall.bartely file cannot be executed with sh... But maybe I still did not understand ipfw... My /etc/rc.firewall.bartely contains rules like: add pass log all from any to 47.11.42.42 add deny log all from any to any And in rc.conf my firewall_type=/etc/rc.firewall.bartleby And I use default firewall_script=/etc/rc.firewall -Arne __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com