From nobody Thu Sep 28 05:00:14 2023 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4Rx1WL2BP9z4vXJ2; Thu, 28 Sep 2023 05:00:14 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R3" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id 4Rx1WL1kwQz3ft4; Thu, 28 Sep 2023 05:00:14 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1695877214; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=E8y8w/Evmb9p1SaZ/fl/9FCY3R5Z/GP6O4dtPljWKKs=; b=q8bHIXeDfN/CzGnPp8Jq7ZbCwlD1YT5S1B3wj9HyYVJj5XtPvXEirYy5MGkOSPvFlx2sm5 Ef0DF+9uyCgwZeqo9CDfICd4uwQQxmAlrBMEW5cQN4x+ClvpElQeOhYeky/TdJ58p7/5SP eieYKwDECr3NzJdKqOQUgVaWbDv7vgQecrkkuf6gXz3DQZSXO4Y2AqDL5U+Ds5l9lb1aeP i6pQmiOXBVOa/b/TimTcG5KOpLiCvA6qPwSc8RPr1qxpb7oe9YEH/FUCp1aYYm9p7I750b ETLc1sAbwCKOmn9Cbi2gEZkUCd8IjNXaPDG1cJYilLzZRisWc3kd3eZB7OVcQg== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1695877214; a=rsa-sha256; cv=none; b=x1vJgv61Gi+1t51Lq83gbizPBmxjb6eCj6BRcZQ0KqutEjZEGQ4q3aeNuG2oiZaM6so8D8 mNvZCgyrdUSNjantUapuiolFd6SCxmG4m1Si11Tw3qAbZpunK6duaAtkPtOVJPrq+bpQFG NgS4H8VTAWtBWFO0k/UpHTRuGrx+GJvXLi6jyvsGish0Yk+MCGdImS+7WC3HSO4zOoX4m6 edeX5m7ibYwjsQgCa8EF6ZiG2pLTu6EaPvnBu10kzDLb9oaVEhoyOTLj3x5AEHZbqs/yvg 4FqIBi7eM/SlAaso9jQgRvykD6VgrvExHSlVCDI+xazQgj8FMBkW2cF7zRb6ew== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1695877214; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=E8y8w/Evmb9p1SaZ/fl/9FCY3R5Z/GP6O4dtPljWKKs=; b=gW6ajDRt72YBX6+St6ReZCYnoVjw2N1jnPg3Sxlm64u/qBhH/ImYGI5RiaXOzxzbAE8cAt COHVOLkvydNHCQWmau9ZbgQ8KWKNpakDwbjvpuxOxuqNDvqPn7Jirjquz6wkSsUAwMlaD0 k8eetmrXMY5bgKnzILtrGnDB11kRvLrOAxBBQRp7wfKwtK+Le7VwwIAz7wACx8FLDr3gO4 9tPhD/d+DNQ7602A+w7eSS40sDrfXUCnk5dIEIec4snqUqh+i9hAhI+gfIqT5+73HfCb9L 3/EQRNFimbgzvcp/pxkTvbapJ3+1tiX9Ar5ElM11CUnILOD09uvhN5+4lDRYNg== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4Rx1WL0qGnz16xG; Thu, 28 Sep 2023 05:00:14 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from gitrepo.freebsd.org ([127.0.1.44]) by gitrepo.freebsd.org (8.17.1/8.17.1) with ESMTP id 38S50Epo030600; Thu, 28 Sep 2023 05:00:14 GMT (envelope-from git@gitrepo.freebsd.org) Received: (from git@localhost) by gitrepo.freebsd.org (8.17.1/8.17.1/Submit) id 38S50EQ5030590; Thu, 28 Sep 2023 05:00:14 GMT (envelope-from git) Date: Thu, 28 Sep 2023 05:00:14 GMT Message-Id: <202309280500.38S50EQ5030590@gitrepo.freebsd.org> To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Zhenlei Huang Subject: git: 12349f38898f - main - ipfw.8: Adjust section for loader tunables List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-dev-commits-src-main@freebsd.org X-BeenThere: dev-commits-src-main@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: zlei X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 12349f38898f231ca803dcf526bac88cb1b5cd2b Auto-Submitted: auto-generated The branch main has been updated by zlei: URL: https://cgit.FreeBSD.org/src/commit/?id=12349f38898f231ca803dcf526bac88cb1b5cd2b commit 12349f38898f231ca803dcf526bac88cb1b5cd2b Author: Zhenlei Huang AuthorDate: 2023-09-28 04:58:44 +0000 Commit: Zhenlei Huang CommitDate: 2023-09-28 04:58:44 +0000 ipfw.8: Adjust section for loader tunables Move the descriptions of loader tunables from section 'SYSCTL VARIABLES' to section 'LOADER TUNABLES'. See also 49197c391b3d (ipfw: Add sysctl flag CTLFLAG_TUN to loader tunables). MFC after: 2 days Differential Revision: https://reviews.freebsd.org/D41981 --- sbin/ipfw/ipfw.8 | 22 +++++++++++----------- 1 file changed, 11 insertions(+), 11 deletions(-) diff --git a/sbin/ipfw/ipfw.8 b/sbin/ipfw/ipfw.8 index 1a042ae2bbbf..e62b8d6efc95 100644 --- a/sbin/ipfw/ipfw.8 +++ b/sbin/ipfw/ipfw.8 @@ -1,5 +1,5 @@ .\" -.Dd April 25, 2023 +.Dd September 28, 2023 .Dt IPFW 8 .Os .Sh NAME @@ -3761,6 +3761,16 @@ or .Xr kenv 1 before ipfw module gets loaded. .Bl -tag -width indent +.It Va net.inet.ip.fw.enable : No 1 +Enables the firewall. +Setting this variable to 0 lets you run your machine without +firewall even if compiled in. +.It Va net.inet6.ip6.fw.enable : No 1 +provides the same functionality as above for the IPv6 case. +.It Va net.link.ether.ipfw : No 0 +Controls whether layer2 packets are passed to +.Nm . +Default is no. .It Va net.inet.ip.fw.default_to_accept : No 0 Defines ipfw last rule behavior. This value overrides @@ -4154,12 +4164,6 @@ Keep dynamic states on rule/set deletion. States are relinked to default rule (65535). This can be handly for ruleset reload. Turned off by default. -.It Va net.inet.ip.fw.enable : No 1 -Enables the firewall. -Setting this variable to 0 lets you run your machine without -firewall even if compiled in. -.It Va net.inet6.ip6.fw.enable : No 1 -provides the same functionality as above for the IPv6 case. .It Va net.inet.ip.fw.one_pass : No 1 When set, the packet exiting from the .Nm dummynet @@ -4176,10 +4180,6 @@ Enables verbose messages. Limits the number of messages produced by a verbose firewall. .It Va net.inet6.ip6.fw.deny_unknown_exthdrs : No 1 If enabled packets with unknown IPv6 Extension Headers will be denied. -.It Va net.link.ether.ipfw : No 0 -Controls whether layer2 packets are passed to -.Nm . -Default is no. .It Va net.link.bridge.ipfw : No 0 Controls whether bridged packets are passed to .Nm .