Wow, I didn't even know there was such a script in /etc/rc.d. I usually do ipf -Fa -f /etc/ipf.conf, whenever my ruleset changes. >> > > /etc/rc.d/ipnat restart ?:) >> > >> > No, no, I can workaround it, I'm just saying it violates POLA to >> > have the packet filter restart bring down the NAT config. >> >> Use "/etc/rc.d/ipfilter reload" instead: