Marco Grigull wrote:
If I want to forward all ip traffic verbatim to a loghost/ids machine, would the following rules suffice?# forward stuff to our loghost/IDS pass in log on $ext_if dup-to $dmz_if all
How's dmz_if defined? did you put the IP of your loghost/IDS in there? If not, I think you should. Cedric