Bug 211928 - [pf] /etc/rc.d/pf should REQUIRE routing
Summary: [pf] /etc/rc.d/pf should REQUIRE routing
Status: New
Alias: None
Product: Base System
Classification: Unclassified
Component: conf (show other bugs)
Version: 11.2-RELEASE
Hardware: Any Any
: --- Affects Only Me
Assignee: freebsd-rc (Nobody)
Keywords: patch
Depends on:
Reported: 2016-08-17 09:10 UTC by Robert Schulze
Modified: 2019-08-14 09:43 UTC (History)
0 users

See Also:

/etc/rc.d/pf: move routing to REQUIRE (299 bytes, patch)
2016-08-17 09:10 UTC, Robert Schulze
no flags Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Robert Schulze 2016-08-17 09:10:27 UTC
Created attachment 173767 [details]
/etc/rc.d/pf: move routing to REQUIRE

When a system with pf_enable="YES" in /etc/rc.conf uses hostnames in /etc/pf.conf, these hostnames cannot be resolved via external nameservers because the default route is not yet set. This results in an empty (all open) ruleset.

Fix: move routing from BEFORE to REQUIRE.

Since r195026 already put netif back to REQUIRE, this change does not affect the issue that the firewall should rather have been setup _before_ any network traffic can occur.

with kind regards,
Robert Schulze