| Main index | Section 4 | Options |
Alternately, to load the file system firewall policy module at boot time, place the following line in your kernel configuration file: options MAC
and in loader.conf(5):
mac_bsdextended_load="YES"
| security.mac.bsdextended.enabled | |
| Set to zero or one to toggle the policy off or on. | |
| security.mac.bsdextended.rule_count | |
| List the number of defined rules, the maximum rule count is current set at 256. | |
| security.mac.bsdextended.rule_slots | |
| List the number of rule slots currently being used. | |
| security.mac.bsdextended.firstmatch_enabled | |
| Toggle between the old all rules match functionality and the new first rule matches functionality. This is enabled by default. | |
| security.mac.bsdextended.logging | |
| Log all access violations via the AUTHPRIV syslog(3) facility. | |
| security.mac.bsdextended.rules | |
| Currently does nothing interesting. | |
The "match first case" and logging capabilities were later added by Tom Rhodes <Mt trhodes@FreeBSD.org>.
| MAC_BSDEXTENDED (4) | May 21, 2005 |
| Main index | Section 4 | Options |
Please direct any comments about this manual page service to Ben Bullock. Privacy policy.
| “ | It's a UNIX system, I know this! | ” |
| — Lex Murphy, Jurassic Park | ||