diff options
Diffstat (limited to 'fw/man')
| -rw-r--r-- | fw/man/fw | 89 |
1 files changed, 61 insertions, 28 deletions
@@ -348,6 +348,44 @@ everything else instead. .PP .B /lib/fw/fw.rc does this in the right order: private namespace, mount, drop, exec. +.SH FAILURE +When +.I fw +dies, the traffic it was filtering stops. +It does not carry on unfiltered. +.PP +Filtering a card, the interface that replaced the card is unbound when +.I fw +stops and the address goes with it, so the machine has no network at +all: the card is bound to nothing and nothing is reading it. +Between two networks, the same happens on both sides and nothing +crosses. +Filtering a namespace, the mount is hung up and every path into +.B /net +fails; the program cannot put the real one back either, because it was +denied +.B #I +before it started \- see +.BR CONTAINMENT . +.PP +This is deliberate, and it is the reason +.I fw +does not try to give the card back as it exits. +A machine that is briefly off the network is a machine somebody +notices; a machine that is briefly on the network with no rules is the +thing the firewall was installed to prevent. +.PP +The cost is that +.I fw +cannot restart unaided: the address it would read off the card is the +address that has just gone. +Give +.B -a +and +.B -g +so that it does not have to read them, and it can be restarted into a +machine it has itself left bare \- see +.BR SUPERVISION . .SH SUPERVISION .I Fw posts its filesystem on @@ -373,6 +411,10 @@ svc=fw.ether0 args=/mnt/fw/ether0 args=-e args=/net/ether0 + args=-a + args=10.0.2.15/24 + args=-g + args=10.0.2.2 args=/lib/fw/host.ndb needs=ipconfig ready=srv:fw.ether0 @@ -395,17 +437,20 @@ What such a mode would buy is a pid to watch, and the name is the better signal: it survives the process that made it and answers the question that matters. .PP -Restarting is not free. -.B Restart=always -will bring +The address and gateway are given here rather than read off the card, +which is the one place that is worth doing. +A .I fw -back, but taking a card is destructive and is not undone, so the card -must be configured again before the new +that has died has taken the address with it, so a restarted .I fw -can read an address off it \- see -.B BUGS -and -.IR ipconfig (8). +has nothing to read; told them, it can restart into the bare card it +left behind, and does \- including clearing away its own control mount, +which a dead +.I fw +leaves behind as a mount that fails everything asked of it. +Without them the restart fails and the machine stays off the network, +which is the safe direction but not a working one. +.PP A copy of this file per card is the shape to use; one .I fw per card is the only shape there is. @@ -549,26 +594,14 @@ so a fragmented IPv6 datagram does not cross. IPv4 fragments do: the first one carries the transport header and decides, and the rest of the datagram inherits what it decided. .PP -Taking a card is destructive and is not undone. -The interface that replaces it is unbound when -.I fw -stops, and the address goes with it, so a -.I fw -that is killed leaves the card bound to nothing and the machine with no -network. -It cannot be restarted unaided either: the address it would have read -off the card is the address that has just been lost, so it must be told -one with -.BR -a , -or the card configured again with -.IR ipconfig (8) -first. -Nothing puts the card back. -Whatever restarts -.I fw -must configure the card first, with the address it had, which +Taking a card is destructive and is not undone, on purpose; see +.BR FAILURE . +A .I fw -no longer knows. +that is killed therefore leaves the machine with no network, and must +be told an address with +.B -a +to start again. .PP The first packet to an unresolved next hop is dropped while .I fw |
