Subject: Re: ip filter and logging
To: Darren Reed <darrenr@reed.wattle.id.au>
From: Andrew Brown <atatat@atatdot.net>
List: tech-net
Date: 04/12/2000 19:57:30
>> it seems to me that i want all the semantics of "pass" (ie, "quick"
>> short circuits and optional "log") but also the byte counts. is there
>> an easier way to do what i'm trying to do?
>
>Accounting rules are processed separately from access control rules.
>
>If you had:
>
>count in blah
>block in blah
>count in foo
>pass in bar
>
>the actual order of application is:
>
>count in blah
>count in foo
>
>block in blah
>pass in bar
ah. ok. that clears it up a little for me.
so (if you'll bear with me) a count line that has a quick on it will
terminate accounting processing and jump straight to access
processing?
hmm...so i actually need a "pass quick" line with each "count quick"
line? and is there some reason that "count log" seems not to work?
or is that simply not done?
--
|-----< "CODE WARRIOR" >-----|
codewarrior@daemon.org * "ah! i see you have the internet
twofsonet@graffiti.com (Andrew Brown) that goes *ping*!"
andrew@crossbar.com * "information is power -- share the wealth."