From owner-freebsd-doc Wed Jul 10 13:53:44 2002 Delivered-To: freebsd-doc@freebsd.org Received: from mx1.FreeBSD.org (mx1.FreeBSD.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id E39C537B400 for ; Wed, 10 Jul 2002 13:53:42 -0700 (PDT) Received: from mailsrv.otenet.gr (mailsrv.otenet.gr [195.170.0.5]) by mx1.FreeBSD.org (Postfix) with ESMTP id D50D243E09 for ; Wed, 10 Jul 2002 13:53:41 -0700 (PDT) (envelope-from keramida@FreeBSD.org) Received: from hades.hell.gr (patr364-a18.otenet.gr [195.167.109.50]) by mailsrv.otenet.gr (8.12.4/8.12.4) with ESMTP id g6AKrbHw000957; Wed, 10 Jul 2002 23:53:38 +0300 (EEST) Received: from hades.hell.gr (hades [127.0.0.1]) by hades.hell.gr (8.12.5/8.12.5) with ESMTP id g6AKra9J004056; Wed, 10 Jul 2002 23:53:36 +0300 (EEST) (envelope-from keramida@FreeBSD.org) Received: (from charon@localhost) by hades.hell.gr (8.12.5/8.12.5/Submit) id g6AKravc004055; Wed, 10 Jul 2002 23:53:36 +0300 (EEST) (envelope-from keramida@FreeBSD.org) Date: Wed, 10 Jul 2002 23:53:36 +0300 From: Giorgos Keramidas To: Chris Pepper Cc: Szilveszter Adam , freebsd-doc@FreeBSD.org Subject: Re: docs/39824: Various tweaks for doc/en_US.ISO8859-1/books/handbook/kernelconfig/chapter.sgml; corresponding comment clarification for GENERIC Message-ID: <20020710205336.GC2739@hades.hell.gr> References: <200207030020.g630K4GZ037338@freefall.freebsd.org> <20020708183507.GE1126@fonix.adamsfamily.xx> <20020708200642.GG1126@fonix.adamsfamily.xx> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: X-Operating-System: FreeBSD 5.0-CURRENT i386 X-PGP-Fingerprint: C1EB 0653 DB8B A557 3829 00F9 D60F 941A 3186 03B6 X-Phone: +30-944-116520 Sender: owner-freebsd-doc@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org On 2002-07-08 16:19 +0000, Chris Pepper wrote: > >AFAIK, ipfw can be made to work in this way too. Some modules even > >should be able to load themselves on-demand before they are first > >needed, but I do not know what are these. (One tip: do not expect > >this method to work with the msdosfs module and a floppy) > > That's a biggie -- all the IPFW docs (man page & handbook) says a > kernel rebuild is required; neither source, nor > /etc/defaults/rc.conf (which provides a bunch of switches to > activate and configure IPFW) provides any information on enabling > the firewall without a kernel rebuild, which I'm told is the *right* > way to do it. Still searching.... Hmmm. Then we should fix the documentation. IPFW works fine as a module, and has been working fine for quite some time. There are a few details one should pay attention to (like kern.securelevel, which might inhibit the loading of modules) but it generally works. What parts of the documentation mention that recompiling a kernel is absolutely necessary to make ipfw(8) work needs fixing :/ - Giorgos To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-doc" in the body of the message