From owner-freebsd-security@FreeBSD.ORG Wed May 28 11:04:30 2003 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id C49CA37B401 for ; Wed, 28 May 2003 11:04:30 -0700 (PDT) Received: from s-smtp-osl-01.bluecom.no (s-smtp-osl-01.bluecom.no [62.101.193.35]) by mx1.FreeBSD.org (Postfix) with ESMTP id 35DAF43F85 for ; Wed, 28 May 2003 11:04:30 -0700 (PDT) (envelope-from erik@pentadon.com) Received: from erik (tromso-dhcp-234-175.bluecom.no [62.101.234.175]) by s-smtp-osl-01.bluecom.no (Postfix) with ESMTP id E8A1F1634F9; Wed, 28 May 2003 20:04:28 +0200 (CEST) From: "Erik Paulsen Skålerud" To: "'Brian Reichert'" Date: Wed, 28 May 2003 20:04:28 +0200 Message-ID: <007d01c32543$94c3c3c0$0a00000a@yes.no> X-Priority: 3 (Normal) X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook, Build 10.0.4510 In-Reply-To: <20030528174703.GW90377@numachi.com> X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1165 Importance: Normal cc: security@freebsd.org Subject: RE: FW: Question about logging. X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 28 May 2003 18:04:31 -0000 > -----Original Message----- > From: Brian Reichert [reichert@numachi.com] > Sent: Wednesday, May 28, 2003 7:47 PM > Subject: Re: FW: Question about logging. > On Wed, May 28, 2003 at 07:41:56PM +0200, Erik Paulsen Skålerud wrote: > > I'm forwarding this to security@, as I'm getting no replies > on ipfw@. > > > > Hope it's relevant enough for you :( > > > > Sorry for asking this, It's probably been asked before, but I've > > searched google for a while now with no results :( I'm wondering if > > it's possible to restrict ipfw to -only- log to /var/log/ipfw.log ? > > Seems like the only way to remove ipfw-logging from the console output > > (dmesg) is to disable the security messages to the console.. Is there > > really no other way? > > It says right in the mapagfe for ipfw(8): > > When a packet matches a rule with the log keyword, a message will > be logged to syslogd(8) with a LOG_SECURITY facility. > > So, unless you modify ipfw iteslf, you get to tune your > syslogd.conf file. Yeah, I've gotten that far. But, how can I explicity -only- filter out ipfw messages from the default console output? Looks like the only way is to remove kern.debug :( Erik. > -- > Brian 'you Bastard' Reichert > 37 Crystal Ave. #303 Daytime number: (603) 434-6842 > Derry NH 03038-1713 USA BSD > admin/developer at large >