bastille
bastille copied to clipboard
[ENHANCEMENT] Support logging in dynamic rdr rules
Is your feature request related to a problem? Please describe.
I usually log connections to my jails. But I can't do this when using bastille rdr
which dynamically inserts the rdr rule using pfctl
.
There doesn't seem to be any support for this. I wanted to check if there was any interest in supporting this before I created a PR
Describe the solution you'd like
I'd like an extension to the current bastille rdr
parameters with something like
Usage: bastille rdr TARGET [clear|list|(tcp|udp host_port jail_port [ log [ ( logopts ) ] ] ) ]
where the log keyword is optional and logopts is defined in the Grammar section of pf.conf
Describe alternatives you've considered
The only alternative I see is to basically use static rdr rules in pf.conf
which isn't ideal in many cases
Additional context
I like this idea but haven't had any time to implement on my own. If you can submit a PR I'll review.
#502 was merged. marking this one as fixed by @nmurali94 .
closing.