only allow global zone control
Brought to you by:
darren_r
it would be nice if ipfilter could be configured from the global zone for local zones and to deny local zones the ability to make any changes.
part of determining the outcome of this is when does the local zone firewall ruleset get loaded?
can, for example, it be loaded by zone name before the zone is constructed and then activated at an appropriate time?