From 3713c294615971d493c304ca2c50b68310d52369 Mon Sep 17 00:00:00 2001 From: henning <> Date: Tue, 29 Jul 2003 17:52:17 +0000 Subject: [PATCH] "pass on lo0" in the intermediate pf ruleset loaded during boot. solves PR3376 by matthew.gream@pobox.com, fix slightly different ok mcbride@ deraadt@ --- src/etc/rc | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/src/etc/rc b/src/etc/rc index 3a6049fe..07ab0b17 100644 --- a/src/etc/rc +++ b/src/etc/rc @@ -1,4 +1,4 @@ -# $OpenBSD: rc,v 1.227 2003/05/14 18:41:06 ian Exp $ +# $OpenBSD: rc,v 1.228 2003/07/29 17:52:17 henning Exp $ # System startup script run by init on autoboot # or after single-user. @@ -120,6 +120,7 @@ ttyflags -a if [ "X${pf}" != X"NO" ]; then RULES="block all" + RULES="$RULES\npass on lo0" RULES="$RULES\npass in proto tcp from any to any port 22 keep state" RULES="$RULES\npass out proto { tcp, udp } from any to any port 53 keep state" RULES="$RULES\npass out inet proto icmp all icmp-type echoreq keep state"