OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • 24.1 Legacy Series »
  • /etc/rc.d/pf: WARNING: /etc/pf.conf is not readable.
« previous next »
  • Print
Pages: [1]

Author Topic: /etc/rc.d/pf: WARNING: /etc/pf.conf is not readable.  (Read 968 times)

verulian

  • Newbie
  • *
  • Posts: 16
  • Karma: 0
    • View Profile
/etc/rc.d/pf: WARNING: /etc/pf.conf is not readable.
« on: March 30, 2024, 09:56:02 pm »
When I was logged into the shell to restart pf, I got the error in the subject line which seems odd/worrisome:



Code: [Select]

root@firewall:~ # service pf onerestart
Disabling pf.
/etc/rc.d/pf: WARNING: /etc/pf.conf is not readable.


As you will see, the file simply isn't there:
Code: [Select]
root@firewall:~ # cat /etc/pf.conf
cat: /etc/pf.conf: No such file or directory

Logged

Patrick M. Hausen

  • Hero Member
  • *****
  • Posts: 6925
  • Karma: 583
    • View Profile
Re: /etc/rc.d/pf: WARNING: /etc/pf.conf is not readable.
« Reply #1 on: March 30, 2024, 10:09:30 pm »
This is not how you restart most services on OPNsense.

Code: [Select]
configctl filter reload
Logged
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

cookiemonster

  • Hero Member
  • *****
  • Posts: 1827
  • Karma: 95
    • View Profile
Re: /etc/rc.d/pf: WARNING: /etc/pf.conf is not readable.
« Reply #2 on: March 30, 2024, 10:12:31 pm »
I am not 100% certain but i imagine that is the location on a vanilla freebsd install of pf but on OPN the command gets issued with the OPN's own location of the config file. That's to say it probably needs issuing either with #service pf onerestart -c /path/to/file or maybe a  template defines it, or even an opn-specific command.
Edit: writing at the same time. There you go.
Logged

verulian

  • Newbie
  • *
  • Posts: 16
  • Karma: 0
    • View Profile
Re: /etc/rc.d/pf: WARNING: /etc/pf.conf is not readable.
« Reply #3 on: March 31, 2024, 12:11:49 pm »
So my issue is that I'm trying to set up a site-to-site WireGuard arrangement. The system I'm referring to is an OPNsense 24.1 install with a singular WAN port. Each time I make any changes that seem to effect the firewall I have to do something to make it responsive again for the web admin interface. I couldn't think of anything to do while I only had LISH (console access via Linode) access except something basic, and this "service pf onerestart" is what worked to push the system into responsiveness again on the web interface. I even found this to be true with direct ssh remote access as well - same problem, had to go to LISH and issue "service pf onerestart" to get ssh to respond...
Logged

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • 24.1 Legacy Series »
  • /etc/rc.d/pf: WARNING: /etc/pf.conf is not readable.
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2024 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2