From owner-freebsd-bugs Sun Jun 30 12:40: 8 2002 Delivered-To: freebsd-bugs@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.FreeBSD.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 1C47D37B400 for ; Sun, 30 Jun 2002 12:40:06 -0700 (PDT) Received: from freefall.freebsd.org (freefall.FreeBSD.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id D2D5B43E13 for ; Sun, 30 Jun 2002 12:40:05 -0700 (PDT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.12.4/8.12.4) with ESMTP id g5UJe4JU020488 for ; Sun, 30 Jun 2002 12:40:04 -0700 (PDT) (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.12.4/8.12.4/Submit) id g5UJe4oa020486; Sun, 30 Jun 2002 12:40:04 -0700 (PDT) Date: Sun, 30 Jun 2002 12:40:04 -0700 (PDT) Message-Id: <200206301940.g5UJe4oa020486@freefall.freebsd.org> To: freebsd-bugs@FreeBSD.org Cc: From: Brooks Davis Subject: Re: misc/40041: firewall and network devices while booting Reply-To: Brooks Davis Sender: owner-freebsd-bugs@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org The following reply was made to PR misc/40041; it has been noted by GNATS. From: Brooks Davis To: Peter Cc: freebsd-gnats-submit@FreeBSD.ORG Subject: Re: misc/40041: firewall and network devices while booting Date: Sun, 30 Jun 2002 12:34:54 -0700 On Sun, Jun 30, 2002 at 12:23:38PM -0700, Peter wrote: > > While booting system is first bringed up network interfaces an than > are initialized firewall rules (ipfw). on booting machine you have > initialized network interface and not initialized firewall for cca 1 > second. in this short time system accepts all traffic from network. I > testing this with ping... If you have "options IPFIREWALL_DEFAULT_TO_ACCEPT" in your kernel, this is what is supposed to happen. Please verify that you don't have this option set. -- Brooks To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-bugs" in the body of the message