Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 19 Mar 2007 14:52:00 -0000
From:      "Greg Hennessy" <Greg.Hennessy@nviz.net>
To:        "'Eric'" <heli@mikestammer.com>, <freebsd-pf@freebsd.org>
Subject:   RE: pf logging differences
Message-ID:  <001d01c76a36$26216710$72643530$@Hennessy@nviz.net>
In-Reply-To: <45FE919B.7040208@mikestammer.com>
References:  <45FE919B.7040208@mikestammer.com>

next in thread | previous in thread | raw e-mail | index | archive | help
> 
> Why is the first host producing more detailed logs? why isnt pf showing
> the port that was blocked or anything else like it does in the first
> host? Is there a way to make the ng0 interface log more or is this due
> to the netgraph hooks into pf?

At a rough guess, you've not got IPV6 compiled into the 2nd system, if not
tcpdump defaults to a snaplen of 64 rather than 96 bytes. 



Greg





Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?001d01c76a36$26216710$72643530$>