I am running IPF on a 13.5-RELEASE system. My rule set has been in use for years and seems to work fine.
Lately I have noticed inbound packets from 10.0.0.0/8 which I find interesting. I would like to get to the bottom of
this so I installed the following rule:
block in log body quick on igb1 inet from 10.0.0.0/8 to any
When I examine ipfilter.log, I do see hits from this rule. What I don't see is any logging of the "body", which should give
me at least some of the packet body. The man page states "Up to 128 bytes of a packet's body can also be
logged with the body keyword." (Section 5, ipf man page )
Any suggestions? Do I misunderstand the man page, or am I otherwise missing something. I would like to figure this out
as I should NOT be getting any packets from 10.0.0.0/8 on my ISP interface. Thanks!
Lately I have noticed inbound packets from 10.0.0.0/8 which I find interesting. I would like to get to the bottom of
this so I installed the following rule:
block in log body quick on igb1 inet from 10.0.0.0/8 to any
When I examine ipfilter.log, I do see hits from this rule. What I don't see is any logging of the "body", which should give
me at least some of the packet body. The man page states "Up to 128 bytes of a packet's body can also be
logged with the body keyword." (Section 5, ipf man page )
Any suggestions? Do I misunderstand the man page, or am I otherwise missing something. I would like to figure this out
as I should NOT be getting any packets from 10.0.0.0/8 on my ISP interface. Thanks!