| Main index | Section 4 | Options |
The pflog0 interface is created when the pflog module is loaded; further instances can be created using ifconfig(8). The pflog module is loaded automatically if both pf(4) and pflogd(8) are enabled.
Each packet retrieved on this interface has a header associated with it of length PFLOG_HDRLEN. This header documents the address family, interface name, rule number, reason, action, and direction of the packet that was logged. This structure, defined in < net/if_pflog.h> looks like
struct pfloghdr {
u_int8_t length;
sa_family_t af;
u_int8_t action;
u_int8_t reason;
char ifname[IFNAMSIZ];
char ruleset[PF_RULESET_NAME_SIZE];
u_int32_t rulenr;
u_int32_t subrulenr;
uid_t uid;
pid_t pid;
uid_t rule_uid;
pid_t rule_pid;
u_int8_t dir;
u_int8_t pad[3];
u_int32_t ridentifier;
};
# ifconfig pflog create pflog1 # ifconfig pflog1 up # tcpdump -n -e -ttt -i pflog1
| PFLOG (4) | October 29, 2021 |
| Main index | Section 4 | Options |
Please direct any comments about this manual page service to Ben Bullock. Privacy policy.
