View Single Post
  #6   (View Single Post)  
Old 2nd June 2010
J65nko J65nko is offline
Join Date: May 2008
Location: Budel - the Netherlands
Posts: 3,507

You could look at the MAC addresses, which reveal the manufacturer of the network device
$ arp -an
? ( at 00:90:d0:83:06:7a on xl0
? ( at 00:08:c7:05:ca:0b on fxp0 static
? ( at 00:19:db:47:b0:4c on fxp0
? ( at 00:11:d8:f1:dd:99 on fxp0
? ( at (incomplete) on fxp0
Then you retrieve

The first MAC from my ARP list is 00:90:d0:83:06:7a. Searching the oui.txt file for 00-90-D0
00-90-D0   (hex)		Thomson Telecom Belgium
0090D0     (base 16)		Thomson Telecom Belgium
As last example the 00:11:d8:f1:dd:99 address:
00-11-D8   (hex)		ASUSTek Computer Inc.
0011D8     (base 16)		ASUSTek Computer Inc.
You don't need to be a genius to debug a pf.conf firewall ruleset, you just need the guts to run tcpdump
Reply With Quote