Subject: kern/5869: ip filtering "keep state" logs too much
To: None <>
From: Michael Graff <>
List: netbsd-bugs
Date: 07/28/1998 20:18:12
>Number:         5869
>Category:       kern
>Synopsis:       ip filtering with "keep state" logs too much
>Confidential:   no
>Severity:       serious
>Priority:       high
>Responsible:    kern-bug-people (Kernel Bug People)
>State:          open
>Class:          sw-bug
>Submitter-Id:   net
>Arrival-Date:   Tue Jul 28 20:20:01 1998
>Originator:     Michael Graff
>Organization:  yes, we do know everything
>Release:        NetBSD 1.3.2
System: NetBSD 1.3.2 NetBSD 1.3.2 (FLAME) #1: Thu Jul 9 00:31:43 PDT 1998 i386

With lines like:

	pass in log quick proto tcp from any to any port = 25 keep state

_all_ packets are logged on that stream.

What would be nice I think is to have a "log-only" to not set the log
bit in the state table, and a "log-state" to only log this packet and
other state transition packets.