Re: Filtering on Ether type, not port
Tuomo Soini <[email protected]>
| Newsgroups | gmane.comp.security.shorewall |
|---|---|
| Organization | Foobar Oy |
| Message-ID | <[email protected]> |
On Wed, 02 Mar 2022 15:47:50 +0000 Peter Humphrey <[email protected]> wrote: > Thank you Ruth. > > On Wednesday, 2 March 2022 15:29:50 GMT Ruth Ivimey-Cook wrote: > > I wouldn't bother trying to filter on type, just filter on either > > FB's (Mac or IP) address (and possibly dest IP) + port as well. I take from this your issue is pure logging of this access. I'd just drop that connection try without logging like this: HTTP(DROP) net:<FB-IP-ADDRESS> $FW -- Tuomo Soini <[email protected]> Foobar Linux services +358 40 5240030 Foobar Oy <https://foobar.fi/>