Chapter 23 • Practical IPv6 Security Solutions 423
23.2.5 CONFIGURING SYSLOG FOR IPF LOGGING
Using the ipmon command, you can specify where you would like IPF to
log activity. If you would like to use syslog to do all IPF logging, follow
these steps.
Open /etc/syslog.conf with your favorite text editor and insert the follow-
ing just above the line that says “!startslip.” Make sure all white spaces are
tabs or syslog will not work.
# IPv4 IPF log local4.info
/var/log/ipf4.log
# IPv6 IPF log local6.info
/var/log/ipf6.log
Now that we have configured IPF logging to use syslog, all we have
to do is create the log files we will be using by running the following
commands.
>touch /var/log/ipf4.log
>touch /var/log/ipf6.log
Restart the syslog process so it will reload ...