Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 09 Dec 2018 15:24:57 +0000
From:      bugzilla-noreply@freebsd.org
To:        bugs@FreeBSD.org
Subject:   [Bug 178482] [ipfw] logging problem from vnet jail
Message-ID:  <bug-178482-227-YCNAkqvzRB@https.bugs.freebsd.org/bugzilla/>
In-Reply-To: <bug-178482-227@https.bugs.freebsd.org/bugzilla/>

index | next in thread | previous in thread | raw e-mail

https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=178482

joeb1@a1poweruser.com changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |joeb1@a1poweruser.com

--- Comment #6 from joeb1@a1poweruser.com ---
Now testing 12.0-RC3. vnet jail running on the gateway host. IPF firewall
running on the gateway host and ipfw running in the vnet jail.

Found out about the undocumented ipfw0 log. This works in each vnet jail
logging the vnet jails log records to the /var/log/security.log file in the
vnet jail.

To enable place the normal ipfw statements in the vnet jails rc.conf with these
changes.

firewall_logging="NO"
firewall_logif="YES"
nohup tcpdump -lnti ipfw0 | logger -t jailname -p security.info &

This method should be documented someplace.

-- 
You are receiving this mail because:
You are the assignee for the bug.

help

Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-178482-227-YCNAkqvzRB>