Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 6 Dec 2025 18:52:45 +0200
From:      Matthias Fechner <idefix@fechner.net>
To:        questions@freebsd.org
Subject:   FreeBSD 15 permission for pfctl
Message-ID:  <df51b950-24f4-47a1-9e0f-ce43f62c1f95@fechner.net>

index | next in thread | raw e-mail

Dear all,

it seems that with FreeBSD 15 there is additional permission required to 
execute pfctl.

With FreeBSD 14 I had in /etc/devfs.conf:
own     pf    root:icinga
perm    pf    0640

this allowed the group icinga to use pfctl, but now I get:
pfctl: Failed to open netlink: Bad file descriptor

does anyone have a idea what additional change in FreeBSD 15 is required 
to allow a normal user to use pfctl to read information about the pf 
firewall?

Thanks a lot!
Matthias



help

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?df51b950-24f4-47a1-9e0f-ce43f62c1f95>