Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 20 Nov 2018 13:50:58 -0500
From:      Ernie Luzar <luzar722@gmail.com>
To:        "freebsd-questions@freebsd.org" <freebsd-questions@freebsd.org>
Subject:   Help with ipfw ipfwlog0
Message-ID:  <5BF45792.8020809@gmail.com>

next in thread | raw e-mail | index | archive | help
In (man ipfw) there is a short blip about the pseudo interface ipfwlog0. 
  Really not enough info to go on.

Here is my problem, when running ipfw firewall on the host and inside of 
a vnet jail the log messages from the jail get intermingled into the 
hosts ipfw log /var/log/security. To test if I can get around this 
design flaw I am thinking that if I set up a pseudo interface ipfwlog0 
in the vnet jail then the ipfw rule log option would log to this log in 
the vnet jail.

Can this be done?
Will the logged packets be written to both logs?

Add  firewall_lofif="YES"  to rc.conf in the vnet jail to create the 
logging-pseudo interface.

Is this going to become a file in /var/log/ipfwlog0 within the vnet jail 
without any manual help?

Thanks for any help on this subject.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?5BF45792.8020809>