From owner-freebsd-net Sun Mar 2 18:20:48 2003 Delivered-To: freebsd-net@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id A9E9237B401 for ; Sun, 2 Mar 2003 18:20:47 -0800 (PST) Received: from pit.databus.com (p70-227.acedsl.com [66.114.70.227]) by mx1.FreeBSD.org (Postfix) with ESMTP id CABEA43FBF for ; Sun, 2 Mar 2003 18:20:46 -0800 (PST) (envelope-from barney@pit.databus.com) Received: from pit.databus.com (localhost [127.0.0.1]) by pit.databus.com (8.12.7/8.12.7) with ESMTP id h232KjFr073847; Sun, 2 Mar 2003 21:20:45 -0500 (EST) (envelope-from barney@pit.databus.com) Received: (from barney@localhost) by pit.databus.com (8.12.7/8.12.7/Submit) id h232KjdD073846; Sun, 2 Mar 2003 21:20:45 -0500 (EST) (envelope-from barney) Date: Sun, 2 Mar 2003 21:20:45 -0500 From: Barney Wolff To: Eric Brunner-Williams in Portland Maine Cc: freebsd-net@FreeBSD.ORG Subject: Re: IPFIREWALL, /dev/ipl and friends Message-ID: <20030303022045.GA73672@pit.databus.com> References: <200303022131.h22LVgtY076746@nic-naa.net> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <200303022131.h22LVgtY076746@nic-naa.net> User-Agent: Mutt/1.4i X-Scanned-By: MIMEDefang 2.30 (www . roaringpenguin . com / mimedefang) Sender: owner-freebsd-net@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org On Sun, Mar 02, 2003 at 04:31:42PM -0500, Eric Brunner-Williams in Portland Maine wrote: > What is the mechanism in 5.0 for creating /dev/{ipauth,ipl,ipstate}? > > < # Firewall > < options IPFIREWALL #firewall > < options IPFIREWALL_VERBOSE #enable logging to syslogd(8) > < options IPFIREWALL_FORWARD #enable transparent proxy support > < options IPFIREWALL_VERBOSE_LIMIT=100 #limit verbosity > < options IPFIREWALL_DEFAULT_TO_ACCEPT #use ipf to close, not open > < > < # Do not decrement the ttl, hide firewall from traceroute class tools > < options IPSTEALTH #support for stealth forwarding > < > 1,82c69,70 > < options SMP # Symmetric MultiProcessor Kernel > < options APIC_IO # Symmetric (APIC) I/O IPFIREWALL and friends are for ipfw, not ipfilter (except IPSTEALTH). 5.0 uses devfs and creates pseudo-devices as needed. -- Barney Wolff http://www.databus.com/bwresume.pdf I'm available by contract or FT, in the NYC metro area or via the 'Net. To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-net" in the body of the message