From owner-freebsd-pf@FreeBSD.ORG Wed Jul 23 21:22:03 2008 Return-Path: Delivered-To: freebsd-pf@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 52B601065676 for ; Wed, 23 Jul 2008 21:22:03 +0000 (UTC) (envelope-from thomas@gibfest.dk) Received: from mail.gibfest.dk (tyknet.dk [80.160.141.33]) by mx1.freebsd.org (Postfix) with ESMTP id 13B968FC17 for ; Wed, 23 Jul 2008 21:22:02 +0000 (UTC) (envelope-from thomas@gibfest.dk) Received: from mail.gibfest.dk (localhost [127.0.0.1]) by mail.gibfest.dk (Postfix) with ESMTP id 8F1E7B907 for ; Wed, 23 Jul 2008 22:57:26 +0200 (CEST) X-Spam-Checker-Version: SpamAssassin 3.2.5 (2008-06-10) on doobie.tyknet.cn.dom X-Spam-Level: X-Spam-Status: No, score=-4.4 required=5.0 tests=ALL_TRUSTED,BAYES_00 autolearn=ham version=3.2.5 Received: from [10.10.1.111] (tykling.tyknet.cn.dom [10.10.1.111]) by mail.gibfest.dk (Postfix) with ESMTP id 80B78B8A6 for ; Wed, 23 Jul 2008 22:57:26 +0200 (CEST) Message-ID: <48879B35.1060905@gibfest.dk> Date: Wed, 23 Jul 2008 22:57:25 +0200 From: Thomas Rasmussen User-Agent: Thunderbird 2.0.0.14 (Windows/20080421) MIME-Version: 1.0 To: freebsd-pf@freebsd.org References: <48876DAD.9080100@optiksecurite.com> <488780A6.4010807@radel.com> In-Reply-To: Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Subject: Re: Why this rule doesn't score a match? X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 23 Jul 2008 21:22:03 -0000 Ivan Petrushev wrote: > Hi Jon, > Aaahhh, I see now - these FROM rules must be TO rules :D > Thank you both for your replies. > > I'm going to monitor the outbond connections as well, but I think I > will be OK then. This was the little stone in the shoe. > I've already managed to let ICMP trough that 'block all' ;) > > Btw, I like the way pflog is working - deploying tcpdump on pflog0 and > track down the logged packets. Is there a way to create another pflog > device and use it for some different rules? I've seen there is an > option to the 'log' keyword - (to pflogX), but I didn't managed to > find out how to create more pflog devices. > > Regards, > Ivan. > Hello, To create another pflog interface do: ifconfig pflog1 create And to create it at boot time add: cloned_interfaces="pflog1" to /etc/rc.conf Regards Thomas