From owner-cvs-all Sun Jan 12 23:59:32 2003 Delivered-To: cvs-all@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id C39EA37B401; Sun, 12 Jan 2003 23:59:30 -0800 (PST) Received: from milla.ask33.net (milla.ask33.net [217.197.166.60]) by mx1.FreeBSD.org (Postfix) with ESMTP id 00EFC43F18; Sun, 12 Jan 2003 23:59:30 -0800 (PST) (envelope-from nick@milla.ask33.net) Received: by milla.ask33.net (Postfix, from userid 1001) id 22FE43ABB65; Mon, 13 Jan 2003 08:59:34 +0100 (CET) Date: Mon, 13 Jan 2003 08:59:34 +0100 From: Pawel Jakub Dawidek To: Matt Dillon Cc: cvs-committers@FreeBSD.org, cvs-all@FreeBSD.org Subject: Re: cvs commit: src/sbin/ipfw ipfw.8 ipfw2.c Message-ID: <20030113075934.GE9430@garage.freebsd.pl> References: <200301120331.h0C3VA2H040455@repoman.freebsd.org> Mime-Version: 1.0 Content-Type: multipart/signed; micalg=pgp-md5; protocol="application/pgp-signature"; boundary="H8ygTp4AXg6deix2" Content-Disposition: inline In-Reply-To: <200301120331.h0C3VA2H040455@repoman.freebsd.org> X-PGP-Key-URL: http://garage.freebsd.pl/jules.asc X-OS: FreeBSD 4.7-STABLE i386 User-Agent: Mutt/1.5.1i Sender: owner-cvs-all@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG --H8ygTp4AXg6deix2 Content-Type: text/plain; charset=iso-8859-2 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable On Sat, Jan 11, 2003 at 07:31:10PM -0800, Matt Dillon wrote: +> It turns out that we do not need to add a new ioctl to unbreak a +> default-to-deny firewall. Simply turning off IPFW via a preexisting +> sysctl does the job. To make it more apparent (since nobody picked up +> on this in a week's worth of flames), the boolean sysctl's have been +> integrated into the /sbin/ipfw command set in an obvious and straightf= orward +> manner. For example, you can now do 'ipfw disable firewall' or +> 'ipfw enable firewall'. This is far easier to remember then the +> net.inet.ip.fw.enable sysctl. And what when securelevel >=3D 3? --=20 Pawel Jakub Dawidek UNIX Systems Administrator http://garage.freebsd.pl Am I Evil? Yes, I Am. --H8ygTp4AXg6deix2 Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (FreeBSD) iQCVAwUBPiJx5j/PhmMH/Mf1AQGeHAP6A0TOcdcJ9tQD8TVkuCIOq9PQxJsmhxPi luZ73KSzJf+5ZtsNDMctn0Agy7OxlDNql4VK6tblWJFZHnRjCi1kACVUL4k9OU+0 VK2RMiLn8Y1hTK1EuEy1c+8WOJk22kQ/mzIubsgFMg9eaPRcQgcFLRtFuT3rjZ0U y8xGUsPaoZs= =TZ/R -----END PGP SIGNATURE----- --H8ygTp4AXg6deix2-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe cvs-all" in the body of the message