From owner-freebsd-bugs@FreeBSD.ORG Thu Dec 2 12:00:52 2004 Return-Path: Delivered-To: freebsd-bugs@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id D87C516A4D2 for ; Thu, 2 Dec 2004 12:00:52 +0000 (GMT) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id B89E243D45 for ; Thu, 2 Dec 2004 12:00:52 +0000 (GMT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.1/8.13.1) with ESMTP id iB2C0q9x054395 for ; Thu, 2 Dec 2004 12:00:52 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.13.1/8.13.1/Submit) id iB2C0qjo054394; Thu, 2 Dec 2004 12:00:52 GMT (envelope-from gnats) Date: Thu, 2 Dec 2004 12:00:52 GMT Message-Id: <200412021200.iB2C0qjo054394@freefall.freebsd.org> To: freebsd-bugs@FreeBSD.org From: Ceri Davies Subject: Re: conf/74610: Hostname resolution failure causes firewall rules to stop loading X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: Ceri Davies List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 02 Dec 2004 12:00:53 -0000 The following reply was made to PR conf/74610; it has been noted by GNATS. From: Ceri Davies To: Maxim Konovalov Cc: bug-followup@freebsd.org Subject: Re: conf/74610: Hostname resolution failure causes firewall rules to stop loading Date: Thu, 2 Dec 2004 11:52:15 +0000 On Thu, Dec 02, 2004 at 02:23:29PM +0300, Maxim Konovalov wrote: > And what is the desired behaviour? Loading the rest of the rules > might be dangerous as well. There are "ipfw -n" and "ipfw set", > and check'n'load approach will solve the problem. I'm not sure - dropping to single-user would have been something. In my case the machine was up with all services running and only half a ruleset loaded, which is not ideal. Perhaps the rules could be passed through "ipfw -n" before they are loaded for real. Ceri -- Only two things are infinite, the universe and human stupidity, and I'm not sure about the former. -- Einstein (attrib.)