Subject: Re: ip filter and logging
To: Darren Reed <>
From: Andrew Brown <>
List: tech-net
Date: 04/12/2000 19:57:30
>> it seems to me that i want all the semantics of "pass" (ie, "quick"
>> short circuits and optional "log") but also the byte counts. is there
>> an easier way to do what i'm trying to do?
>Accounting rules are processed separately from access control rules.
>If you had:
>count in blah
>block in blah
>count in foo
>pass in bar
>the actual order of application is:
>count in blah
>count in foo
>block in blah
>pass in bar
ah. ok. that clears it up a little for me.
so (if you'll bear with me) a count line that has a quick on it will
terminate accounting processing and jump straight to access
processing? i actually need a "pass quick" line with each "count quick"
line? and is there some reason that "count log" seems not to work?
or is that simply not done?
|-----< "CODE WARRIOR" >-----| * "ah! i see you have the internet (Andrew Brown) that goes *ping*!" * "information is power -- share the wealth."