ipfilter netboot problems

randall ehren randall at ucsb.edu
Tue Jun 24 12:06:45 PDT 2003


hi,
 i'm setting up a soekris net4501 machine and during some testing i ran
into a problem. basically, if i compile:

  options     IPFILTER_DEFAULT_BLOCK

 into the kernel then i get the following error during a net boot (pxe):

 nfs send error 65 for xxx.xxx.xxx.xxx:/soekris/

 and then the machine stops booting as it can't continue to load the root
partition

 after hunting and pecking around, i found out this relates to a "NFS
server host unreachable" error...

 my guess was that since i had enabled default blocking by ipfilter, once
ipfilter loads then all network access is cut off until the rules
(/etc/ipf.rules) are applied.

 so is this impossible to do since loading the rules would require
mounting a partition?

 thanks,
 -randall


--
        :// randall s. ehren         :// voice 805.893.5632
        :// systems administrator    :// isber|survey|avss.ucsb.edu
        :// institute for social, behavioral, and economic research



More information about the freebsd-net mailing list