Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 11 Feb 2003 17:47:26 -0600 (CST)
From:      Wm Brian McCane <root@mccons.net>
To:        Jez Hancock <jez.hancock@munk.nu>
Cc:        FreeBSD ISP List <freebsd-isp@FreeBSD.ORG>, Chuck Swiger <cswiger@mac.com>
Subject:   Re: Local package initialization
Message-ID:  <20030211174529.L11540-100000@fw.mccons.net>
In-Reply-To: <20030210125901.GC45355@users.munk.nu>

next in thread | previous in thread | raw e-mail | index | archive | help
Personally, I would feed your stats into cricket so you could have pretty
pictures :).  But, if ipfw does something, as mine does, and if you boot
your firewall in closed mode, as I do, everything that needs the firewall
to be open fails.  This can take a little while to figure out when you are
dinking around at 3am ;)

- brian

On Mon, 10 Feb 2003, Jez Hancock wrote:

> Hi Chuck,
>
> On Sun, Feb 09, 2003 at 04:18:08PM -0500, Chuck Swiger wrote:
> > Jez Hancock wrote:
> > [ ... ]
> > >As an example, if the files in /usr/local/etc/rc.d dir looks like this:
> > >
> > >-rwxr-x---  1 root  wheel   181 Dec 23 22:05 000.mysql-client.sh*
> > >-r-xr-xr-x  1 root  wheel   248 Dec 14 09:26 000.pkgtools.sh*
> > >-r-xr-xr-x  1 root  wheel   307 Jan 19 16:32 100.apache.sh*
> > >-rwxr-x--x  1 root  wheel   316 Nov 11 01:19 200.idled.sh*
> > >-rwxr-x---  1 root  wheel   181 Dec 23 22:05 300.mysql.sh*
> > >-rwxr-xr-x  1 root  wheel  1742 Jan 14 18:03 999.ipfw.sh*
> > >
> > >Then the scripts will be run in the order:
> > >
> > >mysql-client
> > >pkgtools
> > >apache
> > >idled
> > >ipfw
> >
> > Note that the above ordering leaves a window of vulnerability after a
> > system reboot, where the firewall rules are not yet in place.  It's
> > safer to start up the firewall first, and then everything else.
> The ipfw script only counts user traffic for stats - you can
> see the results here:
>
> http://ipfwstats.munk.nu
>
> keep meaning to make that frontend look nicer so I can package it up
> and maybe have it added to the ports eventually.
>
> For pass/block packet filtering I use ipf (which loads up prior to the local
> packages).
>
> Cheers,
>
> Jez
>
> To Unsubscribe: send mail to majordomo@FreeBSD.org
> with "unsubscribe freebsd-isp" in the body of the message
>

+-----------------------------------+------------------------------------------+
He rides a cycle of mighty days, and \ Wm Brian and Lori McCane
represents the last great schizm among\ McCane Consulting
the gods. Evil though he obviously is, \ root@mccons.net
he is a mighty figure, this father of   \ http://freenews.maxbaud.net/
my spirit, and I respect him as the sons \ http://www.sellit-here.com/
of old did the fathers of their bodies.   \ http://recall.maxbaud.net/
    Roger Zelazny - "Lord of Light"        \ http://www.mccons.net/
+-------------------------------------------+----------------------------------+


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-isp" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20030211174529.L11540-100000>