pf rules not being loaded during boot on 7.1-PRERELEASE

Bruce Cran bruce at
Thu Oct 2 20:58:46 UTC 2008

I recently upgraded my i386 router from 7.0 to 7.1-PRERELEASE.  I 
rebooted it today but despite pf_enable="YES" being in /etc/rc.conf no 
rules got loaded during boot, despite pf itself having been enabled:

router# pfctl -s rules
router# pfctl -e -f /etc/pf.conf
pfctl: pf already enabled
[connection is closed due to new rules being loaded]
router# pfctl -s rules
scrub in all fragment reassemble
[... lots of rules listed]

Has anyone else seen this problem, or have I just missed something 
that's changed between 7.0 and 7.1 in the way pf works?

Bruce Cran

