rule def/(short) in tcpdump -e

2014-10-20 Thread Axel Rau
Hi, what does rule def/(short) [uid 0, pid 0] pass in mean in the tcpdumped pflog? Thanks, Axel --- PGP-Key:29E99DD6 ☀ +49 151 2300 9283 ☀ computing @ chaos claudius

Re: rule def/(short) in tcpdump -e

2014-10-20 Thread Henning Brauer
* Axel Rau [2014-10-20 12:30]: > what does > rule def/(short) [uid 0, pid 0] pass in > mean in the tcpdumped pflog? def: matched the implicit default rule short: the reason why the packet was dropped - it was shorter than it should have been, aka pbly truncated (or malicious). grep for PFRES_SHO

Re: rule def/(short) in tcpdump -e

2014-10-20 Thread Axel Rau
Am 20.10.2014 um 12:35 schrieb Henning Brauer : > def: matched the implicit default rule > short: the reason why the packet was dropped - it was shorter than it > should have been, aka pbly truncated (or malicious). grep for > PFRES_SHORT in sys/net/pf*.c for the exact cases. > > when you see pa