synproxy definition in pfctl -si

krad kraduk at gmail.com
Tue May 8 15:48:51 UTC 2012


Hi,

I am looking to track the number of syn packets coming into a system,
as the box in question has pf running and using the synproxy attribute
on tcp services, I hope to be able to use the synproxy field in pfctl
-si. However I cant find a definitive definition of the variable, Ive
looking in the source but haven't have much look in finding where it
is derived. Can anyone shed any light on if my assumption is valid as
without a proper definition of this variable I can't really trust its
output is what i think it is. Alternatively if anyone could suggest an
another  way of tracking inbound syn packets I would be grateful, it
must use base os tools though, ie no ports or other apps required.


Thanks

K


More information about the freebsd-pf mailing list