From owner-freebsd-questions@freebsd.org Sun Dec 9 22:52:41 2018 Return-Path: Delivered-To: freebsd-questions@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id B5AAE133455C for ; Sun, 9 Dec 2018 22:52:41 +0000 (UTC) (envelope-from kudzu@tenebras.com) Received: from mail-qt1-x82d.google.com (mail-qt1-x82d.google.com [IPv6:2607:f8b0:4864:20::82d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id D43258148D for ; Sun, 9 Dec 2018 22:52:40 +0000 (UTC) (envelope-from kudzu@tenebras.com) Received: by mail-qt1-x82d.google.com with SMTP id t13so10404104qtn.3 for ; Sun, 09 Dec 2018 14:52:40 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=tenebras-com.20150623.gappssmtp.com; s=20150623; h=mime-version:references:in-reply-to:from:date:message-id:subject:to; bh=cyJcCMMTHW6wQl5Bz3zNdsynmuUTTluw7JXoO0uv+64=; b=0H6C62M5BdT7MWj5tbqhl4UjoKSkRdPr4p5jRqWcfRBxdx55/AUG8rmoA4HQkhZWuI 2gopiLK3ex2z32vxlis+nOWPTOgmAoqLaEcWeEfalxWE6oXenRGO0plNSINle902w+X/ o+jjW4RtXlxGO/sUhKR1MvKj1U997CLWob6nmjNAojArayBB31QzYzniQX4EQYcN9NOh Wnpi9o01TJiwlCNKwfHxCo+90xMXEVFIujj2HO/v/fw46ELShbM16gAtqw3O8+po1CS2 Vi9jaflFT3plNGzm4jEwFrag6fhYu+gwJhEP2bmGEPsB4cSFSoHMiz4JbHsokTDwB0YV Qe3w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=cyJcCMMTHW6wQl5Bz3zNdsynmuUTTluw7JXoO0uv+64=; b=IVTktFYPqf4OUnB2tE6p9izSl3VVe/dyUZygreuK/G8ETEAzYbRsbXYrCrUSjqQSKs vtB4srBtzUV+9cFm1EfdL288h8Dmx7W+Q2QInbLbOfZTR53yumU8Y46IvrZm3FwnmFjF oZSJKYlyWXGCBR2rGxtk9VoLqeFvDpe901wbTK81SBfLHmV4z6Za7mJqa10mRuqoWOxi m3KM2ClYMv7ZKiKEAvUUi5bsWneuBuXyvXVdn9qrbukQLMMi0ZtbvyqxONS06/GnlNrV Pwg5VBzvUf94Vg6A7vpFt3fq/QCy28Yyq5OHYki4YC1Yao6lYvpgJGWlF9ZTARijGwwq AtvA== X-Gm-Message-State: AA+aEWb2lxFf+aUmUs/GIbyVkCONGpxR2h2MbqehSfzB/BrxyJtCRcPQ e5Za+MjoYpBm1yZYIOt/xYeemXSrLvgyNH8im1wHQslBFeI= X-Google-Smtp-Source: AFSGD/Xn1znOLbaZy7QBsoNgwhEGngtxSLGstDOUtnonkQkmt0u4hPRcSOew1DYPDdpIJ6RWfcw4eHzFeJiOTPFKCXE= X-Received: by 2002:aed:2d26:: with SMTP id h35mr10072613qtd.373.1544395960092; Sun, 09 Dec 2018 14:52:40 -0800 (PST) MIME-Version: 1.0 References: <5C0D594C.2060407@gmail.com> <5C0D65CB.8080602@gmail.com> In-Reply-To: <5C0D65CB.8080602@gmail.com> From: Michael Sierchio Date: Sun, 9 Dec 2018 14:52:03 -0800 Message-ID: Subject: Re: Change IPFW default to allow To: FreeBSD Questions X-Rspamd-Queue-Id: D43258148D X-Spamd-Result: default: False [-5.13 / 15.00]; ARC_NA(0.00)[]; NEURAL_HAM_MEDIUM(-1.00)[-0.999,0]; R_DKIM_ALLOW(-0.20)[tenebras-com.20150623.gappssmtp.com]; FROM_HAS_DN(0.00)[]; TO_MATCH_ENVRCPT_ALL(0.00)[]; NEURAL_HAM_LONG(-1.00)[-1.000,0]; MIME_GOOD(-0.10)[multipart/alternative,text/plain]; PREVIOUSLY_DELIVERED(0.00)[freebsd-questions@freebsd.org]; DMARC_NA(0.00)[tenebras.com]; RCPT_COUNT_ONE(0.00)[1]; TO_DN_ALL(0.00)[]; MX_GOOD(-0.01)[cached: alt1.aspmx.l.google.com]; DKIM_TRACE(0.00)[tenebras-com.20150623.gappssmtp.com:+]; RCVD_IN_DNSWL_NONE(0.00)[d.2.8.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.0.4.6.8.4.0.b.8.f.7.0.6.2.list.dnswl.org : 127.0.5.0]; NEURAL_HAM_SHORT(-0.82)[-0.818,0]; R_SPF_NA(0.00)[]; FROM_EQ_ENVFROM(0.00)[]; RCVD_TLS_LAST(0.00)[]; IP_SCORE(-2.00)[ip: (-7.13), ipnet: 2607:f8b0::/32(-1.50), asn: 15169(-1.30), country: US(-0.09)]; ASN(0.00)[asn:15169, ipnet:2607:f8b0::/32, country:US]; RCVD_COUNT_TWO(0.00)[2] X-Rspamd-Server: mx1.freebsd.org Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable X-Content-Filtered-By: Mailman/MimeDel 2.1.29 X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sun, 09 Dec 2018 22:52:41 -0000 On Sun, Dec 9, 2018 at 10:58 AM Ernie Luzar wrote: > Michael Sierchio wrote: > > sysctl net.inet.ip.fw.default_to_accept=3D1 > > > > On Sun, Dec 9, 2018 at 10:08 AM Ernie Luzar wrote: > > > >> Is there a sysctl nib to reset the ipfw default from deny all to allow > >> all? Some thing that works without rebooting the system. > > > sysctl net.inet.ip.fw.default_to_accept=3D1 doesn't work. > unknown oid > > I believe that has to go in loader.conf and reboot the system to enable. > Yes, it is a read-only tunable. *65>* sudo sysctl net.inet.ip.fw.default_to_accept=3D0 sysctl: oid 'net.inet.ip.fw.default_to_accept' is a read only tunable sysctl: Tunable values are set in /boot/loader.conf --=20 "Well," Brahma said, "even after ten thousand explanations, a fool is no wiser, but an intelligent person requires only two thousand five hundred." - The Mah=C4=81bh=C4=81rata