Date: Thu, 17 Jul 2008 15:33:21 -0700 From: Doug Barton <dougb@FreeBSD.org> To: Daniel Gerzo <danger@FreeBSD.org> Cc: freebsd-net@freebsd.org Subject: Re: etc/rc.firewall6 Message-ID: <487FC8B1.4070003@FreeBSD.org> In-Reply-To: <743720911.20080717222210@rulez.sk> References: <743720911.20080717222210@rulez.sk>
next in thread | previous in thread | raw e-mail | index | archive | help
Daniel Gerzo wrote: > Hello freebsd-net, > > would somebody more knowledgeable then I am in ip6 review this [1] > small patch for /etc/rc.firewall6? May I get an approval from some > src/ committer to commit this (please keep me in the CC: list)? > > Thank you. > > [1] http://cvsup.sk.freebsd.org/~danger/rc.ipfw6.diff > Looks like the right direction to go in for the DNS stuff, yes. About the ntp stuff, 2 questions. First, you did not make the same changes in the NTP section in the second hunk as you did in the first, is that intentional? Second, wouldn't it be better to specify the port number (123) on both sides? NTP uses that same port for sending and receiving queries, and I've always built firewalls that way successfully. Doug -- This .signature sanitized for your protection
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?487FC8B1.4070003>