Subject: Re: ipnat/ipfilter bug?
To: Andrew Doran <ad@netbsd.org>
From: Rasputin <rasputin@idoru.mine.nu>
List: netbsd-users
Date: 05/15/2002 16:32:30
* Andrew Doran <ad@netbsd.org> [020515 15:54]:
> Rasputin <rasputin@idoru.mine.nu> wrote:
> 
> > * Dawid Szymański <dawszy@arhea.net> [020515 15:35]:
> > > On Wed, May 15, 2002 at 12:42:13PM +0100, Rasputin wrote:
> > > => 
> > > => Hi there, I think I've found a bug in the rc scripts on 1.5.3RC_2?
> > > => 
> > > => What seems to happen is that if you restart ipfilter
> > > => after a ruleset change, using '/etc/rc.d/ipfilter restart'
> > > => the NAT tables are flushed but not repopulated.
> > > 
> > > /etc/rc.d/ipnat restart ?:)
> > 
> > No, no, I can workaround it, I'm just saying it violates POLA to
> > have the packet filter restart bring down the NAT config.
> 
> Use "/etc/rc.d/ipfilter reload" instead:

Cheers, works a treat.

Isn't this going to bite a few new users in the ass though?
Maybe its just me....

-- 
Rasputin :: Jack of All Trades - Master of Nuns