diff options
author | 2003-07-29 17:52:17 +0000 | |
---|---|---|
committer | 2003-07-29 17:52:17 +0000 | |
commit | 4dd40d42b2d7a35d730d976c204758812d76471b (patch) | |
tree | 10fd4fba90f3469459cf5517ef57a85a818579a5 | |
parent | sputnik dupe; from Dmitry Bogdan <dsb@uvm.poi.dvo.ru> (diff) | |
download | wireguard-openbsd-4dd40d42b2d7a35d730d976c204758812d76471b.tar.xz wireguard-openbsd-4dd40d42b2d7a35d730d976c204758812d76471b.zip |
"pass on lo0" in the intermediate pf ruleset loaded during boot.
solves PR3376 by matthew.gream@pobox.com, fix slightly different
ok mcbride@ deraadt@
-rw-r--r-- | etc/rc | 3 |
1 files changed, 2 insertions, 1 deletions
@@ -1,4 +1,4 @@ -# $OpenBSD: rc,v 1.227 2003/05/14 18:41:06 ian Exp $ +# $OpenBSD: rc,v 1.228 2003/07/29 17:52:17 henning Exp $ # System startup script run by init on autoboot # or after single-user. @@ -120,6 +120,7 @@ ttyflags -a if [ "X${pf}" != X"NO" ]; then RULES="block all" + RULES="$RULES\npass on lo0" RULES="$RULES\npass in proto tcp from any to any port 22 keep state" RULES="$RULES\npass out proto { tcp, udp } from any to any port 53 keep state" RULES="$RULES\npass out inet proto icmp all icmp-type echoreq keep state" |