Re: displaying rule labels in pf logs

2007-04-20 Thread snowcrash
hi max, A small awk/perl/python/ruby/...-filter should get you running. Simply suck in "pfctl -vvsr" output and build an associative array rule# -> label and then just search and replace. that's an alternative. i'll have to figure out how with which script lang (for lowest overhead on an emb

Re: Please help with pf redirector

2007-04-20 Thread Max Laier
Hello Alex, On Thursday 19 April 2007 14:56, Alex Povolotsky wrote: > I am trying to make kernel-only tcp round-robin proxy. > > The following setup > > rdr on em0 inet proto tcp from any to 89.108.66.9 port = smtp -> > port 25 round-robin > > seemed to me abequate, but it does not work. In state

Re: displaying rule labels in pf logs

2007-04-20 Thread Max Laier
On Friday 20 April 2007 01:37, snowcrash wrote: > i typically tail my pf-log with "tcpdump -vvnei pflog0". > > this, of course, displays the matched "rule #", e.g., > > 2007-04-18 13:07:11.363065 rule 40/0(match): pass in on tun0: (tos > 0x0, ttl 54, id 10, offset 0, flags [DF], proto: U