version 1.308, 2007/12/07 17:13:35 |
version 1.309, 2008/01/09 21:38:19 |
|
|
RULES="$RULES\npass out inet6 proto icmp6 all icmp6-type routersol" |
RULES="$RULES\npass out inet6 proto icmp6 all icmp6-type routersol" |
RULES="$RULES\npass in inet6 proto icmp6 all icmp6-type routeradv" |
RULES="$RULES\npass in inet6 proto icmp6 all icmp6-type routeradv" |
fi |
fi |
RULES="$RULES\npass proto { pfsync, carp }" |
RULES="$RULES\npass proto carp" |
case `sysctl vfs.mounts.nfs 2>/dev/null` in |
case `sysctl vfs.mounts.nfs 2>/dev/null` in |
*[1-9]*) |
*[1-9]*) |
# don't kill NFS |
# don't kill NFS |
|
|
if [ X"${pf}" != X"NO" ]; then |
if [ X"${pf}" != X"NO" ]; then |
if [ -f ${pf_rules} ]; then |
if [ -f ${pf_rules} ]; then |
pfctl -f ${pf_rules} |
pfctl -f ${pf_rules} |
|
fi |
|
# bring up pfsync after the working ruleset has been loaded |
|
if [ -f /etc/hostname.pfsync0 ]; then |
|
. /etc/netstart pfsync0 |
fi |
fi |
fi |
fi |
|
|