During boot we have a protective and restrictive pf ruleset during the time
authorphessler <phessler@openbsd.org>
Wed, 26 Apr 2023 14:28:09 +0000 (14:28 +0000)
committerphessler <phessler@openbsd.org>
Wed, 26 Apr 2023 14:28:09 +0000 (14:28 +0000)
commit6fcd0d88b68750375b1ca3b7ae4a3177d514b49f
tree21d911585c0df4497008844daa02a6a34133101f
parent4fc1a5885d3a21e4c54c535484c12c48c78b585d
During boot we have a protective and restrictive pf ruleset during the time
we are running netstart, and then load the pf.conf ruleset after all of the
interfaces are loaded.

Allow in and out IPv6 neighbor advertisement traffic without state during
that time.

suggestions/OK from saschan@
OK sthen@ kn@ florian@ deraadt@
etc/rc