Re: pf does not log all block

2009-03-09 Thread Maxx Twayne
Thank you all. Thanks to your indications, i've found my problem. It was just a block line (when i really looked at it, i still ask why she was here) which was at the end of my block group. I removed it, and my logging worked fine. Pierre, yes i know all these things. I use pf since OpenBSD 3.4,

Re: pf does not log all block

2009-03-09 Thread Pierre Lamy
Without the "quick" keyword, pf evaluates all of your rules and if a more-permissive rule exists to match the traffic flow, it is used. This is different than some commercial firewalls such as Check Point which stop when the traffic matches a rule, and the rules are processed in order. It's co

Re: pf does not log all block

2009-03-08 Thread patrick keshishian
On Sun, Mar 8, 2009 at 11:12 AM, Maxx Twayne wrote: > Hi, > > I would like to see all blocked packets with pf. And i used this : > > block in log on $ext_if all > block out log all > > But when i read on pflog0 on the pflog file, i didn't got any blocked > packets. > Only the logged pass that i as

pf does not log all block

2009-03-08 Thread Maxx Twayne
Hi, I would like to see all blocked packets with pf. And i used this : block in log on $ext_if all block out log all But when i read on pflog0 on the pflog file, i didn't got any blocked packets. Only the logged pass that i asked. Is there any kind of protection, or i did something wrong ? Tha