From owner-freebsd-questions Tue Oct 15 8:31:10 2002 Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id EBF3337B401 for ; Tue, 15 Oct 2002 08:31:08 -0700 (PDT) Received: from sage-one.net (adsl-65-71-135-137.dsl.crchtx.swbell.net [65.71.135.137]) by mx1.FreeBSD.org (Postfix) with ESMTP id E39B043E88 for ; Tue, 15 Oct 2002 08:31:07 -0700 (PDT) (envelope-from jackstone@sage-one.net) Received: from sagea (sagea [192.168.0.3]) by sage-one.net (8.11.6/8.11.6) with SMTP id g9FFUKf36093; Tue, 15 Oct 2002 10:30:23 -0500 (CDT) (envelope-from jackstone@sage-one.net) Message-Id: <3.0.5.32.20021015103018.0136e5e8@mail.sage-one.net> X-Sender: jackstone@mail.sage-one.net X-Mailer: QUALCOMM Windows Eudora Pro Version 3.0.5 (32) Date: Tue, 15 Oct 2002 10:30:18 -0500 To: budsz , MikeM From: "Jack L. Stone" Subject: Re: About rc.firewall Cc: FreeBSD-Questions In-Reply-To: <20021015151812.GA2025@kumprang.or.id> References: <200210151023430685.13684C4D@home.24cl.com> <20021015135723.GA1427@kumprang.or.id> <200210151023430685.13684C4D@home.24cl.com> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Sender: owner-freebsd-questions@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG At 10:18 PM 10.15.2002 +0700, budsz wrote: >On Tue, Oct 15, 2002 at 10:23:43AM -0400, MikeM wrote: >>The [Oo][Pp][Ee][Nn] syntax allows you to specify Open, oPen, OPen, opeN, >>etc. in rc.conf to configure the type of firewall you want from the samples >>provided in the base install. > >OK thx, So if I use firewall_type="" in /etc/rc.conf, what's relations with >line at /etc/rc.firewall for example [Oo][Pp][Ee][Nn]?, It's enough if I >define firewall type only in /etc/rc.firewall..? > >-- >budsz > Designating the type "open" will make your system set up wide open and can be useful when debugging the rc.firewall script and the kernel has been compiled to "deny all". If you want to the rc.firewall to load and bee effective though, you must modify it for your own use, incuding the proper designations of interfaces, ports, and rules. Best regards, Jack L. Stone, Administrator SageOne Net http://www.sage-one.net jackstone@sage-one.net To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-questions" in the body of the message