Re: logging blocked connections in pf, but no line noise

2005-09-20 Thread jared r r spiegel
On Tue, Sep 20, 2005 at 02:11:44PM +0200, frantisek holop wrote: > hmm, on Mon, Sep 19, 2005 at 06:33:16PM -0600, jared r r spiegel said that > > > > what is the noise exactly? looks like TCP:6346 and UDP:1434 covers about half of that. if you're always doing flags S/SA and keeping state o

Re: logging blocked connections in pf, but no line noise

2005-09-20 Thread frantisek holop
hmm, on Mon, Sep 19, 2005 at 06:33:16PM -0600, jared r r spiegel said that > > this doesn't seem to have the disired effect... > > the rule got translated into > > > > block drop in quick inet from any to xxx.xxx.xxx.255 > > > > and is not stopping all the noise... > > heh.. cable modem? (arpa

Re: logging blocked connections in pf, but no line noise

2005-09-19 Thread jared r r spiegel
On Mon, Sep 19, 2005 at 08:59:48PM +0200, -f wrote: > hmm, on Mon, Sep 19, 2005 at 10:01:58AM -0600, j knight said that > > > i was thinking of making another rule, just below this one: > > > > > > block in > > > block in log from any to $ext_if > > > > Another alternative: > > > > block in quic

Re: logging blocked connections in pf, but no line noise

2005-09-19 Thread -f
hmm, on Mon, Sep 19, 2005 at 10:01:58AM -0600, j knight said that > > i was thinking of making another rule, just below this one: > > > > block in > > block in log from any to $ext_if > > Another alternative: > > block in quick to $ext_if:broadcast > block in log this doesn't seem to have the d

Re: logging blocked connections in pf, but no line noise

2005-09-19 Thread j knight
--- Quoting -f on 2005/09/19 at 17:21 +0200: > hi there, > > i would like to log what was blocked from the outside. > as of now i have the following in my pf.conf: > > block in log > > naturally this is logging too much redundant information. > i would like to restrict the logging only to conne

logging blocked connections in pf, but no line noise

2005-09-19 Thread -f
hi there, i would like to log what was blocked from the outside. as of now i have the following in my pf.conf: block in log naturally this is logging too much redundant information. i would like to restrict the logging only to connections which were refused but at the same time were meant only f