ipf question

2008-07-08 Thread ann kok
Hi all

I am using ipf associated with ippool.  When I need to change 
/etc/ipf/ippool.conf, say add a new member in a group, ippool -F  and ippool -f 
/etc/ipf/ippool.conf doesn't seem to work.  I also tried reloading the ipfilter 
rule by 'ipf -Fa -f /etc/ipf/ipf.conf', but ipf doesn't seem to re-read the 
ippool.conf

The only way that has worked is to 'ipf -D' and then 'ipf -E', manually reload 
ippool and then reload the ipf.conf .  But this is not ideal for me since 
restarting the ipf would flush the state table, thus disconnect existing 
connection.

Is there any way to make change to ippool without dropping connectivity?

Thank you


  
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "[EMAIL PROTECTED]"


basic ipf question

2003-03-31 Thread Redmond Militante
hi 
i have a basic question regarding ipf/ipnat setup.
at the moment my setup is:  

i have a ipf/ipnat box hooked up to a switch, and one internal client hooked up to the 
switch.  the public ip of the internal client is aliased to the external (xl0) nic of 
the ipf/ipnat box.

this is working ok for me.  i would now like to add a second internal client.  i'd 
like to alias the public ip of the second internal client to the external nic (xl0) of 
the ipf/ipnat box, hook the second internal client to the switch and protect it behind 
the ipf/ipnat box in the same way that i do the first internal client machine.

this isn't working for me.  when i add the second alias to the external nic of the 
ipf/ipnat box, change rc.conf on the second internal client, and hook it up to the 
switch, then reboot both internal clients, they freeze up during reboot.  hitting 
ctrl-c during the reboot process forces them to complete the reboot process, but only 
the first - original - internal client is working correctly.  the second - newer - 
internal client doesn't seem to be receiving connectivity.  am i going about this the 
wrong way?

thanks again


pgp0.pgp
Description: PGP signature