From owner-freebsd-questions@FreeBSD.ORG Thu Dec 16 19:57:30 2004 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 5134316A4CE for ; Thu, 16 Dec 2004 19:57:30 +0000 (GMT) Received: from rproxy.gmail.com (rproxy.gmail.com [64.233.170.202]) by mx1.FreeBSD.org (Postfix) with ESMTP id EF84D43D1F for ; Thu, 16 Dec 2004 19:57:29 +0000 (GMT) (envelope-from gibblertron@gmail.com) Received: by rproxy.gmail.com with SMTP id j1so1177913rnf for ; Thu, 16 Dec 2004 11:57:29 -0800 (PST) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:reply-to:to:subject:mime-version:content-type:content-transfer-encoding; b=BwM8RfA4uigkjVGQ0t1+hO6sjQzhGl94MFXSCpvNOhV6D7aBBCpJqogeDyvk6hItiVt8N+bR3Jgt2EkQC5T8XaKeuhLw30uO0nYlCwEvBDQelZdC5Z2nICSJsZs75K1tF4wxLbzTq9w4wZoRElZdWH7eKi0Y+uC4j3PeKemtRVQ= Received: by 10.38.88.68 with SMTP id l68mr1325854rnb; Thu, 16 Dec 2004 11:57:29 -0800 (PST) Received: by 10.38.96.30 with HTTP; Thu, 16 Dec 2004 11:57:29 -0800 (PST) Message-ID: Date: Thu, 16 Dec 2004 11:57:29 -0800 From: patrick To: freebsd-questions@freebsd.org Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit Subject: "ipfw count" equivalent for pf X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: patrick List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 16 Dec 2004 19:57:30 -0000 Hi there, Now that FreeBSD 5.x has pf from OpenBSD, I'm wondering if some of the pf experts can help me with porting a simple ipfw configuration from FreeBSD 4.x to pf in FreeBSD 5.x. On our 4.x servers, we have several rules like: ipfw add count ip from any to x.x.x.x ipfw add count ip from x.x.x.x to any ... to keep track of how much traffic is going through a particular IP address. Every night, I capture the data and zero the counters. Using pf, I'm having a difficult time how to establish a similar ruleset so that I can gather the same sort of data. Someone on the openbsd-misc list told me to "add labels to those rules you want to account traffic on and use `pdfctl -sl` to read their counters." The problem is that I'm not sure how to describe the rules using pf. I suppose the rules should just pass all traffic to and from my external interface, but from all the pf documentation I've read, I can't find an example that seems to do this for me. Can any experts lend a hand here? It seems like this should be dead-easy to do, but like many things from the OpenBSD world, it does not seem to straight-forward to me. Thanks, Patrick