From owner-freebsd-doc@freebsd.org Mon Mar 21 21:39:09 2016 Return-Path: Delivered-To: freebsd-doc@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 390A8AD85B1 for ; Mon, 21 Mar 2016 21:39:09 +0000 (UTC) (envelope-from cwjordandt@gmail.com) Received: from mail-lb0-x22b.google.com (mail-lb0-x22b.google.com [IPv6:2a00:1450:4010:c04::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id B69C5DBB for ; Mon, 21 Mar 2016 21:39:08 +0000 (UTC) (envelope-from cwjordandt@gmail.com) Received: by mail-lb0-x22b.google.com with SMTP id k12so136925323lbb.1 for ; Mon, 21 Mar 2016 14:39:08 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to; bh=dss7T9//+bSv71yBBJIAsi1YBmCWtR2Uxw6EBtntwFY=; b=mxi0fDUla2tHxHVmXiDVd83W9y5k69imOQ3K66oUSWMG8gHD8avWyzgh5CrBZezUVC Bx610+uerGTmepKLZktqqN+wXHR/LE5Fv4T3NccWkSYEtRD4CroVnZnsl7vnadyldcvB wUTJl6KJH606xzVdOzOOrBI68c5t2sKyJNsekpDkl5k5VXLNjbOSGi4Cyy069/zyZWlq 3whADDPRmhX+fQkaW/Truh5GuKKtvRi6amduX2f22MHCXhUrdm9UubT4/bpn5cuVOiOU sedQf1nbiGCImaEz1vuAG0cs5/4TnNMzn41fvJfU84e2dUbLko8Wyy4+0ZBjcRrucA6e QVLA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:date :message-id:subject:from:to; bh=dss7T9//+bSv71yBBJIAsi1YBmCWtR2Uxw6EBtntwFY=; b=kvPP7ybMRR+7U3ReydTur73a/9JE6GIEEt5meyBqCTyKb6XOt6vrcfgGwsUBCfVqK4 lqBoZrQYocZd/rBk3XsPmd2/MprXYwJHercBSEw/ONcQ+ZIq7zlwG9aG7X/9yfKaYyB5 yhutdJEvXgQct0GmKi5udaybTW5EEZpoljCKhBagzcDA4j7NicoawLSKgPbo/qxG5+u+ Ne358iO2r68vVjCjb3MJ9PnUr9IjRhAxwARqzFxwFucO3R+ZYAk4uWxQu2jeQ/pTZ16F c6P7y6+4Jzq0ZuemUqbg3uOjck4+UGlr2oCKJ4o/5OvEEFhh66fuwK3lioJ0kGWmiF+r +54w== X-Gm-Message-State: AD7BkJLWgR06UX07ZyLC8FxdYk1j5cc2oKx3nClqXGNu74bZLFQeaKKezSWygZ/G7Xmrwyw25j16OmtWCYhOCw== MIME-Version: 1.0 X-Received: by 10.25.34.213 with SMTP id i204mr12343082lfi.120.1458596347101; Mon, 21 Mar 2016 14:39:07 -0700 (PDT) Received: by 10.25.170.198 with HTTP; Mon, 21 Mar 2016 14:39:07 -0700 (PDT) In-Reply-To: <1458577873.3661.20.camel@canodus.be> References: <1458577873.3661.20.camel@canodus.be> Date: Mon, 21 Mar 2016 17:39:07 -0400 Message-ID: Subject: Re: Handbook section 29.4.1 Enabling IPFW From: Chris Jordan To: freebsd-doc@freebsd.org Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable X-Content-Filtered-By: Mailman/MimeDel 2.1.21 X-BeenThere: freebsd-doc@freebsd.org X-Mailman-Version: 2.1.21 Precedence: list List-Id: Documentation project List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 21 Mar 2016 21:39:09 -0000 On Mon, Mar 21, 2016 at 12:31 PM, Wout Decr=C3=A9 wrote: > On Mon, 2016-03-21 at 11:38 -0400, Chris Jordan wrote: > > I'm coming back to FreeBSD after many years away and I am setting up a > new > > system with 10-2-release. > > > > I was reading through Handbook section 29.4.1 "Enabling IPFW" and it > says: > > "To enable logging, include this line in > > /etc/rc.conf: firewall_logging=3D"YES"". That didn't seem to work for = me, > so > > I went looking through /etc/rc.firewall, and found it's looking for a > line > > like "firewall_logdeny=3D"YES" instead, but it's only checking for that= for > > the case where firewall_type=3D"workstation". > > IPFW logging is enabled in /etc/rc.d/ipfw: > > if checkyesno firewall_logging; then > echo 'Firewall logging enabled.' > sysctl net.inet.ip.fw.verbose=3D1 >/dev/null > fi > > Should work putting firewall_logging=3D"YES" in rc.conf. By default, logs > are written to /var/log/security. > > Ah, I see, thanks. The difference is that when I set "firewall_logdeny=3D"YES"" in rc.conf, then /etc/rc.firewall both sets net.inet,ip.fw.verbose=3D1 and sets a firewall rule for "65500 deny log logamount 500 ip from any to any", while if I set "firewall_logging=3D"YES"= " then the firewall rule is "65500 deny ip from any to any" so nothing gets logged. I suppose it's not a problem if you're modifying /etc/rc.firewall to set your own rules anyway, but in the simple case it's a bit unclear. I've only tried it where "firewall_type=3D"workstation"", the other firewall_types appear to have different default logging behavior. Chris Jordan