<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: Reset PF Firewall Automatically While Testing Configuration With Remote Server Over SSH Session</title> <atom:link href="http://www.cyberciti.biz/faq/freebsd-openbsd-reset-pf-firewall-automatically/feed/" rel="self" type="application/rss+xml" /><link>http://www.cyberciti.biz/faq/freebsd-openbsd-reset-pf-firewall-automatically/</link> <description>Every answer asks a more beautiful question.</description> <lastBuildDate>Fri, 10 Feb 2012 19:55:56 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>By: Nilesh</title><link>http://www.cyberciti.biz/faq/freebsd-openbsd-reset-pf-firewall-automatically/#comment-54943</link> <dc:creator>Nilesh</dc:creator> <pubDate>Mon, 17 Jan 2011 10:16:00 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=3791#comment-54943</guid> <description>Saviour!</description> <content:encoded><![CDATA[<p>Saviour!</p> ]]></content:encoded> </item> <item><title>By: eigenheit</title><link>http://www.cyberciti.biz/faq/freebsd-openbsd-reset-pf-firewall-automatically/#comment-42194</link> <dc:creator>eigenheit</dc:creator> <pubDate>Tue, 23 Jun 2009 01:22:30 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=3791#comment-42194</guid> <description>Thinking about it the  command -nf is very useful in testing new rules, you are  always kept  behind  your trustful gateway.</description> <content:encoded><![CDATA[<p>Thinking about it the  command -nf is very useful in testing new rules, you are  always kept  behind  your trustful gateway.</p> ]]></content:encoded> </item> <item><title>By: gregf</title><link>http://www.cyberciti.biz/faq/freebsd-openbsd-reset-pf-firewall-automatically/#comment-41600</link> <dc:creator>gregf</dc:creator> <pubDate>Wed, 13 May 2009 22:53:50 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=3791#comment-41600</guid> <description>This is great, although you might already have a working rule set. In which case you wouldn&#039;t want to take down the whole firewall over a mistake. My working method has been about the same as above, but I keep new rules in there own file pf.testing. Then you can do the 120 second delay to load the original set if things went wrong. This way there is no open hole(s) in your firewall while your testing. Obviously it&#039;s highly unlikely you&#039;ll have an attack the moment you bring the firewall down. I just think it&#039;s better practice if there is a choice.</description> <content:encoded><![CDATA[<p>This is great, although you might already have a working rule set. In which case you wouldn&#8217;t want to take down the whole firewall over a mistake. My working method has been about the same as above, but I keep new rules in there own file pf.testing. Then you can do the 120 second delay to load the original set if things went wrong. This way there is no open hole(s) in your firewall while your testing. Obviously it&#8217;s highly unlikely you&#8217;ll have an attack the moment you bring the firewall down. I just think it&#8217;s better practice if there is a choice.</p> ]]></content:encoded> </item> </channel> </rss>
