pooh.ASARian.org security run output (lots of wrong arp messages)

Lowell Gilbert freebsd-questions-local at be-well.no-ip.com
Wed Jul 9 11:08:30 PDT 2003


John Murphy <jfm at blueyonder.co.uk> writes:

> Fuzzy <fuzzy at pooh.ASARian.org> wrote:
> >
> >Is there any way to convince the kernel not to log these
> >incorrect arp messages?
> >
> >currently we have...
> >net.link.ether.inet.log_arp_wrong_iface: 1
> >
> >Is there a different sysctl or variable for rc.conf
> >to stop it from logging incorrect information?
> 
> Indeed there is but only in 5.0 or greater I believe.  It's called:
> 
> net.link.ether.inet.log_arp_movements

Actually, both of those are available in -STABLE.
However, it's usually better to fix the source of the address changes,
if it's under your control.


More information about the freebsd-questions mailing list