Unix Technical Forum

Re: time-based pf rules in crontab do not survive a reboot (naturally)?

This is a discussion on Re: time-based pf rules in crontab do not survive a reboot (naturally)? within the lucky.openbsd.misc forums, part of the OpenBSD category; --> On Sun, Jul 16, 2006 at 02:40:04AM +0300, Soner Tari wrote: > However, if you agree with me, I ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > lucky.openbsd.misc

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-18-2008, 06:46 AM
Darrin Chandler
 
Posts: n/a
Default Re: time-based pf rules in crontab do not survive a reboot (naturally)?

On Sun, Jul 16, 2006 at 02:40:04AM +0300, Soner Tari wrote:
> However, if you agree with me, I get the feeling that all of these are
> inelegant workarounds compared to the ideal solution: time support in pf
> (similar to perhaps iptables). I've read the replies from developers to
> a similar question a few months back, and they were not interested in
> adding such support in pf. I am sure there are other priorities for
> them, and it's totally OK with me.
>
> But time rules are important for me, so ultimately I'd like to achieve
> the correct solution, if I can (which is the OpenBSD way after all).
> Therefore, I am even willing to play with the pf source code to add time
> support just for packet filtering rules. I am sure, if it were so easy,
> we would probably have it by now. So, before I attempt it myself, do you
> guys think it is too difficult?
> the case, hopefully?


Consider that pf does its job, and does it well. Other tools can be used
to manipulate the policy that pf enforces, changing over not only time
but any other criteria. Such criteria can't be foreseen and certainly
all of them can't (and shouldn't) be included in pf.

Small, focused tools are one example of the Unix way (not just OpenBSD).
You can build the behavior you're asking for with the tools you have
currently, and do it in a robust manner. Thinking through how that would
work, I don't find it inelegant. It would be clear and easy to manage.

--
Darrin Chandler | Phoenix BSD Users Group
dwchandler@stilyagin.com | http://bsd.phoenix.az.us/
http://www.stilyagin.com/ |

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 10:34 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0
www.UnixAdminTalk.com