Robert Watson <rwat...@freebsd.org> writes:
> This sounds right to me, FWIW -- being able to fully configure the
> policy before network traffic starts is definitely right in the
> abstract, it's just a question of getting there...

One option would be to start pf with a pre-cooked rule set that allows
only DHCP and nd6 / rtsol or similar, then load the user-provided rule
set once all interfaces are up.

DES
-- 
Dag-Erling Smørgrav - d...@des.no
_______________________________________________
svn-src-all@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/svn-src-all
To unsubscribe, send any mail to "svn-src-all-unsubscr...@freebsd.org"

Reply via email to