OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Dries Schellekens (gwyllionace.ulyssis.org)
Date: Tue Jun 04 2002 - 03:26:45 CDT

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    On Mon, 3 Jun 2002, Yacketta, Ronald wrote:

    > Folks,
    >
    > I have the pflog0 device and the /dev/pf device but yet I am not getting
    > any log information in /var/log/pflog when I add the log or log-all flag
    > to any rule in pf.conf
    >
    > Any ideas why nothing is being logged? I can tcpdump the interface and
    > see traffic for that specific port

    Try apropos pflog, you'll see pflogd(8) packet filter logging daemon.

    Are what about reading the part about logging in pf.conf(5)?
    LOGGING
         ...
         The logged packets are sent to the pflog0 interface. This interface is
         monitored by the pflogd(8) logging daemon which dumps the logged packets
         to the file /var/log/pflog in tcpdump(8) binary format.
         ...

    There are plenty of mans that point to pflogd(8).

    # ifconfig pflog0 up
    # pflogd

    Cheers,

    Dries

    -- 
    Dries Schellekens
    email: gwyllionulyssis.org