21st March 2012
|
|
More noise than signal
|
|
Join Date: May 2008
Location: USA
Posts: 7,983
|
|
- Log both your pass rules as well as your block rules.
- # tcpdump -neti pflog0 host ip.address.of.interest
You will see block/pass rules applied to initial state packets for that IP address. If PF rules do not seem to point to a problem source, then use tcpdump(8) on the NIC:
- # tcpdump -neti nic host ip.address.of.interest
|