how do I delete just one ipfw rule ?

Julian Elischer julian at elischer.org
Tue Sep 9 10:45:56 PDT 2003



On Tue, 9 Sep 2003, Josh Brooks wrote:

> 
> 
> 
> On Tue, 9 Sep 2003, Luigi Rizzo wrote:
> 
> > no, it is not possible to delete them -- you have no way to tell
> > which rule to delete when multiple rules share the same number.
> 
> Are there any plans to make ipfw more flexible by changing the 65535 to
> the next power of two ?  So there are a lot more rules ?

The rule number is only 16 bits long..

This is made use of in 'divert' where the rule number that caused the
divert is in the port-number field when you do a recvfrom().
if you change this, it won't work..

On "sendto()" teh rule number is used to suggest where the packet
"re-enters" the filter. if you pass it back unchanged then 
it reenters the filter at the next rule after the one that diverted it..
(i.e. where it left off)


> 
> _______________________________________________
> freebsd-net at freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-net
> To unsubscribe, send any mail to "freebsd-net-unsubscribe at freebsd.org"
> 



More information about the freebsd-net mailing list