On Mon, Mar 27, 2006 at 11:52:59AM +0200, Luca Losio wrote: > is there a way to force pf just to log the header and not the whole > packet? I'm doing a sniffer and I can't log alle the packets but I > want at least the headers....
That would be the pcap(3) snaplen, as set with -s with tcpdump(8) and pflogd(8), for instance. A default of 96 bytes is sufficient for IP and most protocol headers. Daniel
