"Perry E. Metzger" <perry@piermont.com> writes: > > Having to explicitly turn ip_filter *on* is a bug, in some environments. > > Indeed. You don't want packets to leak during bootup. Can you turn it on before the interfaces are configured? If so, that seems like a workable solution. --Michael