Identifying traffic logged by ipfw

From: Ben Beuchler (insyte_at_emt-p.org)
Date: 04/16/04

  • Next message: Jonathon McKitrick: "Re: How do I eliminate resolver delay??"
    Date: Fri, 16 Apr 2004 12:51:31 -0500
    To: freebsd-questions@freebsd.org
    
    

    I'm working on a new bridging firewall using ipfw on FBSD 5.1. The goal
    is to default to closed with a few exceptions. To test my ruleset, I end
    with this rule:

    add 420 allow log ip from any to any

    The idea is that by watching the logs I could see what protocols I forgot
    to create rules for. This is what I'm getting in the logs:

    Apr 16 16:43:40 bfw kernel: ipfw: 420 Accept MAC in via em2

    I'm guessing this means it's matching non-ip traffic, but I couldn't find
    any info to confirm this. Is there any sort of trick I could use to log
    the entire packet? Since nothing about the source or destination was
    logged, I don't have enough info to create a tcpdump filter. Perhaps some
    sort of divert rule?

    Thanks!

    -Ben

    -- 
    Ben Beuchler                                           There is no spoon.
    insyte@emt-p.org                                            -- The Matrix
    _______________________________________________
    freebsd-questions@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-questions
    To unsubscribe, send any mail to "freebsd-questions-unsubscribe@freebsd.org"
    

  • Next message: Jonathon McKitrick: "Re: How do I eliminate resolver delay??"

    Relevant Pages

    • Re: POTM post of the month nomination
      ... VBM: Your arguments are thoughtful. ... exceptions to that rule. ... dyed-in-the-wool theist because he used God in a metaphorical sense. ... impossible things through some sort of metaphysical bookkeeping trick. ...
      (talk.origins)
    • Re: reasons to use else inside rescue
      ... I think that sort of control structure would see a lot of use when ... With synchronous exceptions, it's a little less useful since you ... I suspect this is because it's not a well known ... feature and ends up making the code a bit harder to understand. ...
      (comp.lang.ruby)
    • Re: An article for Fedhaters
      ... though there may be some exceptions that I'm ... My use of it was sort of correct: ... communicating with native English speakers. ...
      (rec.sport.tennis)
    • Re: OT- weird caffeine- spelling
      ... neither financier seized either species of weird leisure ... This is the sort of mmemonic that I was thinking of. ...
      (rec.food.cooking)