>From what I can tell, ipfw's 'flush' command clears the ruleset *and* the
current list of dynamic (keep-state) rules.  Is there any way to ask ipfw to
flush only the ruleset, but to leave the dynamic rules intact?  Ideally,
ipfw could be made to compare the curreny dynamic rules against any new
rules that were added, which would allow a sysadmin to implement a new
ruleset on an already-running system without disturbing any current valid
connections.  Is such a thing possible, or am I dreaming?
-- 
Kirk Strauser
In Googlis non est, ergo non est.

To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-questions" in the body of the message

Reply via email to