*BSD News Article 60699


Return to BSD News archive

Path: euryale.cc.adfa.oz.au!newshost.anu.edu.au!harbinger.cc.monash.edu.au!news.mel.connect.com.au!munnari.OZ.AU!news.hawaii.edu!ames!hookup!news.mathworks.com!news.kei.com!nntp.coast.net!news.net99.net!news.pcslink.com!ryan
From: ryan@pcslink.com (Ryan Mooney)
Newsgroups: comp.unix.bsd.freebsd.misc
Subject: ipfw Logging - does it work?
Date: Mon, 05 Feb 96 08:22:25 GMT
Organization: Phoenix Computer Specialists
Lines: 35
Message-ID: <4f4erv$ftu@news.pcslink.com>
NNTP-Posting-Host: ryan.pcslink.com
X-Newsreader: News Xpress Version 1.0 Beta #3


I am trying to get logging to work with the ipfw code in 2.1
I have compiled the kernel with IPFIREWALL and IPFIREWALL_VERBOSE
(and just for kicks DEBUG_IPFIREWALL).  I have then set up some filters
that do explicit denies:
  ipfw lreject tcp from any to 206.43.161.32/27 7,9,13,19
or
  ipfw ldeny tcp from any to 206.43.161.32/27 7,9,13,19
(tried both)
BUT nothing is logged anywhere (this is a printf should show
up on the screen right? NO - OK I have kern.*	/var/log/blah
in syslog.conf [with blah appropriately touched]).  Also
when I do an 
  ipfw l f 
I don't see the filters BUT if I try to hit those ports it
fails (as it should) when the filters are there but succeds
when they are not (again as it should).  Problem is they
don't log and I can't see the damn things in the output list.

Anyone have any ideas on this (I'm just about going crazy trying to
figure it out).

THANKS in advance

Also PLEASE reply to me personally as my newsfeed is rather unreliable
and I may not get your helpfull message (and that would really suck IMHO :)

----------------------------------------------------------------------------
Ryan Mooney                  ryan@pcslink.com
Systems Engineer
Phoenix Computer Specialists Internet Provider     "Illuminate The 
Opposition!"
Phone (602)265-9188          Fax (602)265-9357        -- Adam Weishaupt
proud member of AAAAAA - American Association Against Acronym Abuse Anonymous.
----------------------------------------------------------------------------