From owner-freebsd-ipfw@FreeBSD.ORG Tue Sep 27 18:05:20 2005 Return-Path: X-Original-To: freebsd-ipfw@freebsd.org Delivered-To: freebsd-ipfw@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id A644316A41F for ; Tue, 27 Sep 2005 18:05:20 +0000 (GMT) (envelope-from ap@bnc.net) Received: from mailomat.net (mailomat.net [217.110.117.101]) by mx1.FreeBSD.org (Postfix) with ESMTP id 78CFB43D60 for ; Tue, 27 Sep 2005 18:05:18 +0000 (GMT) (envelope-from ap@bnc.net) X-SpamCatcher-Score: 2 [X] Received: from [194.39.192.125] (account bnc-mail@mailrelay.mailomat.net HELO bnc.net) by mailomat.net (CommuniGate Pro SMTP 4.3.6) with ESMTPSA id 5578491 for freebsd-ipfw@freebsd.org; Tue, 27 Sep 2005 20:05:11 +0200 X-BNC-SpamCatcher-Score: 2 [X] Received: from [194.39.192.247] (account ap HELO [194.39.192.247]) by bnc.net (CommuniGate Pro SMTP 4.3.5) with ESMTPSA id 1230753 for freebsd-ipfw@FreeBSD.ORG; Tue, 27 Sep 2005 20:05:10 +0200 Mime-Version: 1.0 (Apple Message framework v734) In-Reply-To: <200509271712.j8RHCspb008088@lurza.secnetix.de> References: <200509271712.j8RHCspb008088@lurza.secnetix.de> Content-Type: text/plain; charset=US-ASCII; delsp=yes; format=flowed Message-Id: <7247A1D7-DCB4-493D-B28A-8E98A21C3983@bnc.net> Content-Transfer-Encoding: 7bit From: Achim Patzner Date: Tue, 27 Sep 2005 20:05:06 +0200 To: freebsd-ipfw@FreeBSD.ORG X-Mailer: Apple Mail (2.734) Cc: Subject: Re: Enable ipfw without rebooting X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 27 Sep 2005 18:05:20 -0000 > Do you have IPFW code in your kernel? (Either statically > compiled via kernel config, or dynamically loaded as KLD) > > If you don't, then it doesn't work, of course. > > Try loading the IPFW KLD ("kldload ipfw"). And remember - doing a "shutdown -r +10" before trying might be a good idea - last time I did this I found out the hard way that the kernel module was built with a default action of "deny all from any to any". There were only 800 km between me and the server. Of course. Achim