From owner-freebsd-net@FreeBSD.ORG Mon Jul 28 21:44:16 2008 Return-Path: Delivered-To: net@FreeBSD.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 75660106567C; Mon, 28 Jul 2008 21:44:16 +0000 (UTC) (envelope-from jhb@FreeBSD.org) Received: from server.baldwin.cx (bigknife-pt.tunnel.tserv9.chi1.ipv6.he.net [IPv6:2001:470:1f10:75::2]) by mx1.freebsd.org (Postfix) with ESMTP id 0D7A68FC16; Mon, 28 Jul 2008 21:44:15 +0000 (UTC) (envelope-from jhb@FreeBSD.org) Received: from localhost.corp.yahoo.com (john@localhost [IPv6:::1]) (authenticated bits=0) by server.baldwin.cx (8.14.2/8.14.2) with ESMTP id m6SLhwaA004973; Mon, 28 Jul 2008 17:44:09 -0400 (EDT) (envelope-from jhb@FreeBSD.org) From: John Baldwin To: bug-followup@FreeBSD.org, netch@netch.kiev.ua Date: Mon, 28 Jul 2008 16:25:57 -0400 User-Agent: KMail/1.9.7 MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Content-Disposition: inline Message-Id: <200807281625.58108.jhb@FreeBSD.org> X-Greylist: Sender succeeded SMTP AUTH authentication, not delayed by milter-greylist-2.0.2 (server.baldwin.cx [IPv6:::1]); Mon, 28 Jul 2008 17:44:10 -0400 (EDT) X-Virus-Scanned: ClamAV 0.93.1/7868/Mon Jul 28 14:31:43 2008 on server.baldwin.cx X-Virus-Status: Clean X-Spam-Status: No, score=-2.5 required=4.2 tests=AWL,BAYES_00,NO_RELAYS autolearn=ham version=3.1.3 X-Spam-Checker-Version: SpamAssassin 3.1.3 (2006-06-01) on server.baldwin.cx Cc: net@FreeBSD.org Subject: Re: bin/65258: [patch] [request] save /etc/rc.firewall from changing for standard firewall types X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 28 Jul 2008 21:44:16 -0000 An updated patch is available at http://www.FreeBSD.org/~jhb/patches/firewall_rc_conf.patch. I'm not sure that we need to have the default values in /etc/rc.firewall anymore though with this patch. I think I'd rather make the script error out if any of the required values aren't supplied. Also, I updated the description of the other firewall toggles that are only for the "workstation" type to indicate as such in their comments. -- John Baldwin