Project

General

Profile

Actions

Bug #1282

closed

Default drop policy should log?

Added by rancor rancor about 13 years ago. Updated about 13 years ago.

Status:
Rejected
Priority:
Normal
Assignee:
-
Category:
-
Target version:
-
Start date:
02/14/2011
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
2.0
Affected Architecture:

Description

I have spent hours of debug different network configurations and VPN configurations (IPsec and OpenVPN) just to find out that I was making a very simple mistake but since I got "blind" my own mistake I didn't realize what wrong I did.

I was mislead by my own conception that all factory DROP statement was with LOG option but when I used pfctl -srules I saw what the problem was.

It's maybe not a bug but it's at least a humble feature request to change all default drop statements with LOG option to make it more simple to debug what's going on. At least on advanced tab for the firewall settings it should be an option to add LOG to all drop statements.

Best regards rancor

Actions

Also available in: Atom PDF