[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

man ipf and /etc/rc.conf

Why does "man ipf" (and FAQ) say:

     ... the following command will flush the kernel's current
     ruleset, install the new ruleset, and enable (-E) ipf:

           ipf -Fa -f /etc/ipf.rules -E

     (This is the exact command executed by the /etc/rc script at 
      boot-time if ipfilter=YES in /etc/rc.conf.)

But if I look into the file /etc/netstart, I see only:

    # Configure the IP filter before configuring network interfaces
    if [ X"${ipfilter}" = X"YES" -a -f "${ipfilter_rules}" ]; then
            echo 'configuring IP filter'
            ipf -Fa -f ${ipfilter_rules}

ie. without the -E switch? I ask this, because I have let the lines

   ipnat=NO                # for "YES" ipfilter must also be "YES"
   ipfilter_rules=/etc/ipf.rules   # Rules for IP packet filtering
   ipnat_rules=/etc/ipnat.rules    # Rules for Network Address Translation

in the /etc/rc.conf and am starting the ipf and ipnat in the
/etc/ppp/ppp.linkup file instead:

    ! /sbin/ipf -Fa -f /etc/ipf.rules
    ! /sbin/ipnat -CF -f /etc/ipnat.rules

And if I use the switch -E above, I get a warning that ipf 
is already enabled (but I wonder how? I have "ipfilter=NO").