From owner-freebsd-questions@FreeBSD.ORG Tue Sep 12 20:45:30 2006 Return-Path: X-Original-To: freebsd-questions@freebsd.org Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 3989B16A407 for ; Tue, 12 Sep 2006 20:45:30 +0000 (UTC) (envelope-from cswiger@mac.com) Received: from smtpout.mac.com (smtpout.mac.com [17.250.248.182]) by mx1.FreeBSD.org (Postfix) with ESMTP id B1B2643D78 for ; Tue, 12 Sep 2006 20:45:29 +0000 (GMT) (envelope-from cswiger@mac.com) Received: from mac.com (smtpin07-en2 [10.13.10.152]) by smtpout.mac.com (Xserve/8.12.11/smtpout12/MantshX 4.0) with ESMTP id k8CKjE9f019069; Tue, 12 Sep 2006 13:45:14 -0700 (PDT) Received: from [17.214.13.96] (a17-214-13-96.apple.com [17.214.13.96]) (authenticated bits=0) by mac.com (Xserve/smtpin07/MantshX 4.0) with ESMTP id k8CKjCHR003998; Tue, 12 Sep 2006 13:45:13 -0700 (PDT) In-Reply-To: References: <7269D41C-C334-44DC-9549-ACB28F79014A@chrononomicon.com> <20060912160830.b7a91061.wmoran@collaborativefusion.com> Mime-Version: 1.0 (Apple Message framework v752.2) Content-Type: text/plain; charset=US-ASCII; delsp=yes; format=flowed Message-Id: Content-Transfer-Encoding: 7bit From: Chuck Swiger Date: Tue, 12 Sep 2006 13:45:11 -0700 To: Bart Silverstrim X-Mailer: Apple Mail (2.752.2) X-Brightmail-Tracker: AAAAAQAAA+k= X-Language-Identified: TRUE Cc: FreeBSD Mailing Lists Subject: Re: forwarding as a gateway, logging certain traffic X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 12 Sep 2006 20:45:30 -0000 On Sep 12, 2006, at 1:37 PM, Bart Silverstrim wrote: >> Better to use something like: >> >> ipfw add 1 log tcp from any to me 25 setup >> >> If Bart would like to use tcpdump for the same purpose, consider >> running something like: >> >> tcpdump -nt 'port 25 and (tcp[tcpflags] & tcp-syn != 0)' > > Maybe my ipfw is old; it kept telling me that "log" is an invalid > action. However, I think I may be able to get the tcpdump idea to > work. There's a kernel option you need to enable for IPFW to do logging. If you're kldload'ing the ipfw module, it probably wasn't compiled with IPFW_LOGGING or whatever the exact name is. Anyway, tcpdump should be your friend. :-) -- -Chuck