Re: And I have two interfaces...

From: erik van westen (erik_at_geenspam.vanwesten.net.invalid)
Date: 08/23/04


Date: Mon, 23 Aug 2004 12:17:15 +0200

Johnathan Doe wrote:

> ... which are rl0 (ethernet card) and tun0 which is my external interface
> (I think... don't know really.)
>
> |-------------|
> | |-----|
> | Obsd box | eth |------------| ADSL Modem
> | |-----|
> |-------------|
>
>
> That's my set-up.

So start to use tcpdump on pflog0 to see what is being blocked... Logging
all blocks will help you.

EJ

-- 
Remove geenspam. to email
See http://www.vanwesten.net for examples pf and ipf
(IPv4 and IPv6 website)


Relevant Pages

  • Re: TCPDUMP ... Logging far too much traffic ?
    ... > in/out my network via TCPDUMP (ip headers atleast). ... the amount of data is silly!! ... I don't see any point in logging tons of data and mechanically ...
    (Security-Basics)
  • Re: Watching /var/log/pflog grow
    ... EITHER logged by pflogd ... XOR displayed by tcpdump. ... If yes, /var/log/pflog would be incomplete, because some packets ... would have been snatched away from pflog0 by tcpdump, ...
    (freebsd-questions)
  • Re: Snort producing tcpdump unreadable binary files.
    ... You should actually be using "snort -r" to read the files and not "tcpdump ... > had to do with RedHat Linux machines, and the fact that they changed ... > Any advice will be greatly appreciated, as I am currently logging in ...
    (FreeBSD-Security)
  • pf not logging on 5.3-BETA3 ?
    ... I can access pflog0 and there I will see entries that are matching the ... I've added device pf, pfsync, pflog to the kernel, and have the following ... tcpdump: verbose output suppressed, use -v or -vv for full protocol decode ... But it won't write the blocked/logged entries to the logfile. ...
    (freebsd-current)
  • Re: attack alert on port 1080
    ... this is a stealth syn attack. ... > I can watch the log files as portsentry continues to log the attempts, ... > but tcpdump shows nothing. ... logging of packets caught by a rule ...
    (RedHat)