Skip to content

Commit 2268e76

Browse files
committed
ipfw: don't use 'log' parameter.
I guess we were causing the kernel to syslog on every single packet on MacOS. Oops.
1 parent a8b71f6 commit 2268e76

File tree

1 file changed

+4
-4
lines changed

1 file changed

+4
-4
lines changed

firewall.py

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -243,11 +243,11 @@ def do_ipfw(port, dnsport, subnets):
243243
for swidth,sexclude,snet in sorted(subnets, reverse=True):
244244
if sexclude:
245245
ipfw('add', sport, 'skipto', xsport,
246-
'log', 'tcp',
246+
'tcp',
247247
'from', 'any', 'to', '%s/%s' % (snet,swidth))
248248
else:
249249
ipfw('add', sport, 'fwd', '127.0.0.1,%d' % port,
250-
'log', 'tcp',
250+
'tcp',
251251
'from', 'any', 'to', '%s/%s' % (snet,swidth),
252252
'not', 'ipttl', '42', 'keep-state', 'setup')
253253

@@ -289,12 +289,12 @@ def do_ipfw(port, dnsport, subnets):
289289
for ip in nslist:
290290
# relabel and then catch outgoing DNS requests
291291
ipfw('add', sport, 'divert', sport,
292-
'log', 'udp',
292+
'udp',
293293
'from', 'any', 'to', '%s/32' % ip, '53',
294294
'not', 'ipttl', '42')
295295
# relabel DNS responses
296296
ipfw('add', sport, 'divert', sport,
297-
'log', 'udp',
297+
'udp',
298298
'from', 'any', str(dnsport), 'to', 'any',
299299
'not', 'ipttl', '42')
300300

0 commit comments

Comments
 (0)