HomeFreeBSD

pf: Convert PF_DEFAULT_TO_DROP into a vnet loader tunable 'net.pf.

Description

pf: Convert PF_DEFAULT_TO_DROP into a vnet loader tunable 'net.pf.default_to_drop'

7f7ef494f11d introduced a compile time option PF_DEFAULT_TO_DROP to make
the pf(4) default rule to drop. While this change exposes a vnet loader
tunable 'net.pf.default_to_drop' so that users can change the default
rule without re-compiling the pf(4) module.

This change is similiar to that for IPFW [1].

  1. 5f17ebf94db5 Convert IPFW_DEFAULT_TO_ACCEPT into a loader tunable 'net.inet.ip.fw.default_to_accept'

Reviewed by: network, kp
MFC after: 2 weeks
Relnotes: yes
Differential Revision: https://reviews.freebsd.org/D39866

Details

Provenance
zleiAuthored on Sep 22 2023, 10:05 AM
Reviewer
network
Differential Revision
D39866: pf: Introduce a new vnet loader tunable net.pf.default_to_drop
Parents
rG36468371ce95: pkgbase: Fix ucl for libcompiler_rt
Branches
Unknown
Tags
Unknown