Hi gang,
I suspect this to be a bug, but before I submit a report I figured I'd ask around here first:
(edit) => Forgot to include my system specs:
root@vbsd:/home/peter # uname -a
FreeBSD vbsd.intranet.lan 15.1-RELEASE-p3 FreeBSD 15.1-RELEASE-p3 releng/15.1-n283611-88e7371d9dc2 GENERIC amd64
Secure level 3 should block firewall rule changes, but surely you should be able to still view them? IMO it would otherwise seriously defeat the purpose of security if you can't even confirm that your firewall is actually active.
I suspect this to be a bug, but before I submit a report I figured I'd ask around here first:
Code:
root@vbsd:/home/peter # grep pf /boot/loader.conf /etc/rc.conf
/boot/loader.conf:pf_load="YES"
/boot/loader.conf:pflog_load="YES"
/etc/rc.conf:pf_enable="YES"
/etc/rc.conf:pflog_enable="YES"
root@vbsd:/home/peter # pfctl -sr
root@vbsd:/home/peter # sysctl kern.securelevel=3
kern.securelevel: -1 -> 3
root@vbsd:/home/peter # pfctl -sr
pfctl: Operation not permitted
root@vbsd:/home/peter #
(edit) => Forgot to include my system specs:
root@vbsd:/home/peter # uname -a
FreeBSD vbsd.intranet.lan 15.1-RELEASE-p3 FreeBSD 15.1-RELEASE-p3 releng/15.1-n283611-88e7371d9dc2 GENERIC amd64
Secure level 3 should block firewall rule changes, but surely you should be able to still view them? IMO it would otherwise seriously defeat the purpose of security if you can't even confirm that your firewall is actually active.