Re: Dynamic IPFW Rules

From: Josef Karthauser (joe@tao.org.uk)
Date: 10/18/01


Date: Thu, 18 Oct 2001 12:50:03 +0100
From: Josef Karthauser <joe@tao.org.uk>
To: Dag-Erling Smorgrav <des@ofug.org>


On Thu, Oct 18, 2001 at 01:12:46PM +0200, Dag-Erling Smorgrav wrote:
> "Crist J. Clark" <cristjc@earthlink.net> writes:
> > Yeah. I said I would do that (what was I thinking?), but I was waiting
> > on Luigi to finish his updates in -CURRENT and MFCs.
>
> You can merge up to rev 1.109 if you also merge the kernel changes
> that correspond to rev 1.90. They've been in -CURRENT long enough.
> The only problem is that this will break binary compatibility because
> struct ipfw has changed, and good luck trying to skip rev 1.90 -
> you'll get nothing but conflicts.

I'd be interested in taking a look at doing this if no other
committers have time. I rely quite heavilily on ipfw on -stable,
and have already hacked in the change that supressed the timed out
dynamic rules from the 'ipfw show' output.

Or is someone else working on this already? I don't want to tread on
anyone's toes.

Joe



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Relevant Pages

  • Re: New preview patch for ipfw to pfil_hooks conversion
    ... >> new patch to fix this problem against ipfw with pfilhooks if that's ... >> what it's going to take to get a fix committed. ... I've mailed Luigi. ... I know that keeping private patches ...
    (freebsd-current)
  • Re: New preview patch for ipfw to pfil_hooks conversion
    ... >> new patch to fix this problem against ipfw with pfilhooks if that's ... >> what it's going to take to get a fix committed. ... I've mailed Luigi. ... I know that keeping private patches ...
    (freebsd-net)
  • Re: Large number of http connections immediately dropped
    ... Do you run ipfw? ... We didn't see this problem after recompiling without SMP support and waiting for a day or two, but that immediately brought the load average up to around 50 and made it much slower, so that's clearly not a solution. ...
    (freebsd-performance)
  • Re: FreeBSD 8: ipfw fwd and pf route-to broken?
    ... >from ipfw is sucked into rtalloc1_fibat last with zero length and ... Returning sin_len into sbin/ipfw resolves issue. ... sin_len setting was removed in revision 1.146 by luigi. ...
    (freebsd-net)

Loading