It will work, you just won't have a working firewall. I filed a PR
about this after discovering that ipf wasn't filtering _any_ packets
coming in. Yech. If you have a static address it may not be an
issue. I use dial-on-demand as well, but with a dynamic address.
- Mike H.
Date: Mon, 26 Mar 2001 12:20:40 +0100
From: Rasputin <[EMAIL PROTECTED]>
Reply-To: Rasputin <[EMAIL PROTECTED]>
Content-Type: text/plain; charset=us-ascii
Sender: [EMAIL PROTECTED]
X-Loop: FreeBSD.ORG
Precedence: bulk
* Mike Harding <[EMAIL PROTECTED]> [010325 20:06]:
>
> You can specify interfaces by name in your rules - but you have to
> issue 'ipf -y' to sync up with interface address changes. I've done
> this with a dial-up line by putting 'ipf -y' in /etc/rc.network at the
> end of pass 1. This file should be updated in the distribution so
> that this happens automatically or ppp users may not see any packet
> filtering!
Well I've been using ipf on a dialup for a year now, and don't have an ipf -y
anywhere in my config files. Maybe it's because I use tun0 demand-dialling?
Or is the manpage (man 1 ipf) correct?
-y (SOLARIS 2 ONLY) Manually resync the in-kernel
^^^^^^^^^^^^^^^
interface list maintained by IP Filter with the
current interface status list.
Either the manpage or the ppp linkup fiels should be modified, I reckon.
--
Rasputin
Jack of All Trades :: Master of Nuns
To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-stable" in the body of the message
To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-stable" in the body of the message