Ahh, wrong file. diag_logs_filter.php What's the version on this file.
On 12/26/05, David Strout <[EMAIL PROTECTED]> wrote: > # head /usr/local/www/diag_logs.php > #!/usr/local/bin/php > <?php > /* $Id: diag_logs.php,v 1.32.2.2 2005/12/21 > 22:12:39 sullrich Exp $ */ > /* > diag_logs.php > > > > > Actually, I don't see why this would be > happening. > > > > What version does diag_logs.php show at the top > for it's id? > > > > /* $Id: blah blah */ > > > > On 12/26/05, Scott Ullrich <[EMAIL PROTECTED]> > wrote: > > > Are you sure these are the matching records? > I see differences. > > > > > > On 12/26/05, David Strout > <[EMAIL PROTECTED]> wrote: > > > > Here is the enhanced log: > > > > > > > > Dec 26 13:37:39 WAN 24.39.130.241.3129 > > > > 24.39.185.78.445 ESP > > > > Dec 26 13:37:36 WAN 24.39.130.241.3129 > > > > 24.39.185.78.445 ESP > > > > Dec 26 13:35:38 WAN 66.101.95.241:16246 > > > > 24.39.185.78:1026 UDP > > > > > > > > And here is the raw log: > > > > > > > > Dec 26 13:37:39 pf: 2. 955773 rule > 35/0(match): > > > > block in on fxp1: 24.39.130.241.3129 > > > > > 24.39.185.78.445: S 452106698:452106698(0) > win > > > > 16384 <mss 1460,nop,nop,sackOK> > > > > Dec 26 13:37:36 pf: 118. 730692 rule > 35/0(match): > > > > block in on fxp1: 24.39.130.241.3129 > > > > > 24.39.185.78.445: S 452106698:452106698(0) > win > > > > 16384 <mss 1460,nop,nop,sackOK> > > > > Dec 26 13:35:38 pf: 53. 763178 rule > 35/0(match): > > > > block in on fxp1: 66.101.95.241.16246 > > > > > 24.39.185.78.1026: UDP, length 791 > > > > > > > > -- > > > > David L. Strout > > > > Engineering Systems Plus, LLC > > > > > > > > ----- Original Message ----- > > > > Subject: Re: [pfSense Support] BETA1 error > > > > reporting protocal in firewall logs > > > > From: [EMAIL PROTECTED] > > > > To: support@pfsense.com > > > > Date: 12-26-2005 1:37 pm > > > > > > > > > > > > > Turn on raw logs and compare. Please show > me a > > > > line where it is matching false. > > > > > > > > > > My logs here only show TCP and UDP and > some > > > > ICMP. > > > > > > > > > > On 12/26/05, David Strout > <[EMAIL PROTECTED]> > > > > wrote: > > > > > > I have notices since installing BETA1 > that the > > > > > > firewall logs report "NEARLY" everything > as > > > > ESP > > > > > > protocol. I have hit the outside of pfS > with > > > > many > > > > > > packets and nmap'd the outside interface > and > > > > all > > > > > > reports as ESP protocol. > > > > > > > > > > > > Thoughts? > > > > > > > > > > > > -- > > > > > > David L. Strout > > > > > > Engineering Systems Plus, LLC > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > > --------------------------------------------------------------------- > > > > > > To unsubscribe, e-mail: > > > > [EMAIL PROTECTED] > > > > > > For additional commands, e-mail: > > > > [EMAIL PROTECTED] > > > > > > > > > > > > > > > > > > > > > > > > > > > --------------------------------------------------------------------- > > > > > To unsubscribe, e-mail: > > > > [EMAIL PROTECTED] > > > > > For additional commands, e-mail: > > > > [EMAIL PROTECTED] > > > > > > > > > > > > > > > > > --------------------------------------------------------------------- > > > > To unsubscribe, e-mail: > [EMAIL PROTECTED] > > > > For additional commands, e-mail: > [EMAIL PROTECTED] > > > > > > > > > > > > > > > > --------------------------------------------------------------------- > > To unsubscribe, e-mail: > [EMAIL PROTECTED] > > For additional commands, e-mail: > [EMAIL PROTECTED] > > > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [EMAIL PROTECTED] > For additional commands, e-mail: [EMAIL PROTECTED] > > --------------------------------------------------------------------- To unsubscribe, e-mail: [EMAIL PROTECTED] For additional commands, e-mail: [EMAIL PROTECTED]