From 2b48205e685a7c6af92bbeb97bbf7cbc48561849 Mon Sep 17 00:00:00 2001 From: dhartmei <> Date: Thu, 23 May 2002 20:47:57 +0000 Subject: [PATCH] Sigh, add the rule in the right place (not just when NFS is used). From Dries Schellekens --- src/etc/rc | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/src/etc/rc b/src/etc/rc index d9624305..928c5939 100644 --- a/src/etc/rc +++ b/src/etc/rc @@ -1,4 +1,4 @@ -# $OpenBSD: rc,v 1.194 2002/05/23 19:38:18 dhartmei Exp $ +# $OpenBSD: rc,v 1.195 2002/05/23 20:47:57 dhartmei Exp $ # System startup script run by init on autoboot # or after single-user. @@ -120,12 +120,12 @@ ttyflags -a if [ "X${pf}" != X"NO" ]; then RULES="block in all\nblock out all" + RULES="$RULES\npass in proto tcp from any to any port 22 keep state" case `sysctl vfs.mounts.nfs 2>/dev/null` in *[1-9]*) # don't kill NFS RULES="$RULES\npass in proto udp from any port { 111, 2049 } to any" RULES="$RULES\npass out proto udp from any to any port { 111, 2049 }" - RULES="$RULES\npass in proto tcp from any to any port 22 keep state" ;; esac echo $RULES | pfctl -R - -e