Safe IPFW ruleset

Michael Sierchio kudzu at tenebras.com
Tue Dec 9 21:31:25 PST 2003


Steve Bertrand wrote:
> Does anyone have a preferred method for a safe ipfw reload while a few
> hundred miles away from the server. I have tried a few, but would like
> some personal experiences.

Use IPFW2 and the atomic swapping of sets.

You may also add rules that get matched prior to
the current ruleset (in a different set) and diable
the original set when convenient.



More information about the freebsd-ipfw mailing list