Re: Interpreting Logs

2010-07-11 Thread Remko Lodder
On Jul 11, 2010, at 7:34 AM, Doug Hardie wrote: > I have not been able to find any real information on the contents of the > logs. My logs show a number of interesting entries that I just can't find > any information to explain. For example: > > loose state match > > BAD ICMP 11:0 > > stat

Re: Interpreting Logs

2010-07-11 Thread Doug Hardie
On 11 July 2010, at 02:17, Remko Lodder wrote: > > On Jul 11, 2010, at 7:34 AM, Doug Hardie wrote: > >> I have not been able to find any real information on the contents of the >> logs. My logs show a number of interesting entries that I just can't find >> any information to explain. For ex

Re: Interpreting Logs

2010-07-11 Thread Remko Lodder
>> I believe I used pfctl -x m although it might have been u. >From the manual page it seems you did the 'm': -x urgent Generate debug messages only for serious errors. -x misc Generate debug messages for various errors. That generates messages for various types o

Re: Interpreting Logs

2010-07-11 Thread Doug Hardie
I am trying to understand what pf is trying to tell me. Its generating those messages for a reason. The volume of them depends on how many rules have log in them and how often they are invoked. On 11 July 2010, at 23:12, Remko Lodder wrote: > > >>> I believe I used pfctl -x m although it

Re: Interpreting Logs

2010-07-11 Thread Daniel Hartmeier
On Sun, Jul 11, 2010 at 11:20:42PM -0700, Doug Hardie wrote: > I am trying to understand what pf is trying to tell me. Its generating those > messages for a reason. The volume of them depends on how many rules have log > in them and how often they are invoked. Some explanations can be found