Les Desser <leslie@[127.0.0.1]> wrote:
> Thanks. Done that and indeed it now logs. Unfortunately, it only logs
> the IP addresses after DNS lookup while the 814 used to log the actual
> site names. Don't suppose anything can be done about that as it seems
> to be logging the firewall rules, which are only applied after the DNS
> lookup.
Yes - I think this is correct. The DG814 didn't have a true firewall or
customisable logging and I guess this is a penalty for improved functionality!
> Incidentally, does anyone know the limits to the number of firewall
> rules?
No - but I have several setup. For imformation it is possible to log
EVERY outgoing connection by setting up a "Custom service" called, for
example, "AllPorts" which includes TCP/UDP ports 1->65535. I have this but
I then had to add several "don't log" rules (at higher priority) to prune
out things like DNS lookups to keep the log from groing too fast!
|