Logging and IPFW

Wayne Pascoe freebsd-questions at penguinpowered.org
Tue Sep 9 05:10:11 PDT 2003


On Tue, Sep 09, 2003 at 09:42:14PM +1000, John Birrell wrote:
> On Tue, Sep 09, 2003 at 12:34:47PM +0100, Wayne Pascoe wrote:
> > However, I am still not seeing anything in /var/log/messages when I
> > portscan the machine. The firewall appears to be working, as we receive
> > nothing back on the portscanning machine, but I would like logging
> > enabled. 
> 
> Have you added the 'log' keyword to your rules?
> 
> e.g:
> 
>         # Reject&Log all setup of incoming connections from the outside
>         ${fwcmd} add deny log tcp from any to any in via ${oif} setup
> 
> The log entries will be written to /var/log/security.

I tried changing the rc.firewall script so that the last line in the
CLIENT section read
${fwcmd} add 65535 deny ip from any to any log
but ipfw list still just showd
65535 deny ip from any to any log

where should that rule with the log go in the list ? Before the last
line ? 

Should I add a rule before 65535 that logs things ? 

Thanks,

-- 
Wayne Pascoe
'tis far easier to get forgiveness than it is to
get permission - probably someone famous,
but more often, my Dad.


More information about the freebsd-questions mailing list