Being even more suspicious of my own abilities...

> I usually use the inactive/active tables
> 
>       ipf -I -Fa -f /etc/ipf.conf
> 
> If all is well and no errors occur, I swap the active/inactive with

...I do the same so far, but then...

ipf -s; sleep 30; ipf -s

and attempt to reestalish a new control connection to the machine.
If *this* works, I then do the final

> ipf -s

to permamently activate the new set of rules.

-- 
        David Pick

Reply via email to