* Jesus Sanchez [2008-05-16 17:45]:
of course not. you disabled pf, then enabled it again. no ruleset
reload.
> I needed to use this instead with my actual config:
that is not the right way either. you disable pf, then load a new
ruleset and enable it again. the whole disable-enable dance it useless
and leaves a timeframe where no firewalling takes place, but traffic
flows. you just do pfctl -f /etc/pf.conf, it does the right thing for
you (load new ruleset, atomically switch to it, ditch old one)
--
Henning Brauer, hb@bsws.de, henning@openbsd.org
BS Web Services, http://bsws.de
Full-Service ISP - Secure Hosting, Mail and DNS Services
Dedicated Servers, Rootservers, Application Hosting - Hamburg & Amsterdam
| debian developer | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Greg KH | [GIT PATCH] driver core patches against 2.6.24 |
| H. Peter Anvin | Re: [PATCH] x86: Construct 32 bit boot time page tables in native format. |
| Christoph Lameter | Re: [RFC 00/15] x86_64: Optimize percpu accesses |
git: | |
| Christoph Hellwig | Re: [PATCH 06/32] IGET: Mark iget() and read_inode() as being obsolete [try #2] |
| Jarek Poplawski | Re: [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
| David Miller | [GIT]: Networking |
