Why not log message for upd protocal rule?
Posted on 2008-10-06
I have created an IPFilter rule file. Most rules are TCP protocal based while few are for UDP. For instnce,
block return-rst in log quick proto tcp from any to any port = 1521
blcok return-rst in log quick proto udp from any to any port = 1812
The log file is configured as /var/log/ipflog through /etc/syslog.conf file.
I am using freeware IPPx to send packets to my test machine. The IPPx GUI tool can send both TCP and UPD packets. However, I can see the log message for matched TCP ports, but NOT for UDP ports. So I can not verify whether the IPFilter has filtered out traffic to that UDP. Do you know why?