summaryrefslogtreecommitdiff
path: root/docs/configuration/firewall
diff options
context:
space:
mode:
authorRobert Göhler <github@ghlr.de>2023-03-23 13:28:10 +0100
committerGitHub <noreply@github.com>2023-03-23 13:28:10 +0100
commit3eec7410884492fcd5f3b46928932a2ec6d8037a (patch)
tree66ecbff7aa3e5ab1060701d3e15507acae45bc0e /docs/configuration/firewall
parentb9ed2ba6500a5fc0084e1f96acd583467c8964f9 (diff)
parente56a7c86ecb83390a881ec7f4e0207bed2c75557 (diff)
downloadvyos-documentation-3eec7410884492fcd5f3b46928932a2ec6d8037a.tar.gz
vyos-documentation-3eec7410884492fcd5f3b46928932a2ec6d8037a.zip
Merge pull request #967 from nicolas-fort/fwall_log-options
T5050: firewall: add log-options in firewall docs
Diffstat (limited to 'docs/configuration/firewall')
-rw-r--r--docs/configuration/firewall/general.rst31
1 files changed, 27 insertions, 4 deletions
diff --git a/docs/configuration/firewall/general.rst b/docs/configuration/firewall/general.rst
index 9cd747b5..c217ba6c 100644
--- a/docs/configuration/firewall/general.rst
+++ b/docs/configuration/firewall/general.rst
@@ -335,13 +335,36 @@ the action of the rule will be executed.
Enable or disable logging for the matched packet.
-.. cfgcmd:: set firewall name <name> rule <1-999999> log-level [emerg |
- alert | crit | err | warn | notice | info | debug]
-.. cfgcmd:: set firewall ipv6-name <name> rule <1-999999> log-level [emerg |
- alert | crit | err | warn | notice | info | debug]
+.. cfgcmd:: set firewall name <name> rule <1-999999> log-options level
+ [emerg | alert | crit | err | warn | notice | info | debug]
+.. cfgcmd:: set firewall ipv6-name <name> rule <1-999999> log-options level
+ [emerg | alert | crit | err | warn | notice | info | debug]
Define log-level. Only applicable if rule log is enable.
+.. cfgcmd:: set firewall name <name> rule <1-999999> log-options group
+ <0-65535>
+.. cfgcmd:: set firewall ipv6-name <name> rule <1-999999> log-options group
+ <0-65535>
+
+ Define log group to send message to. Only applicable if rule log is enable.
+
+.. cfgcmd:: set firewall name <name> rule <1-999999> log-options snaplen
+ <0-9000>
+.. cfgcmd:: set firewall ipv6-name <name> rule <1-999999> log-options snaplen
+ <0-9000>
+
+ Define length of packet payload to include in netlink message. Only
+ applicable if rule log is enable and log group is defined.
+
+.. cfgcmd:: set firewall name <name> rule <1-999999> log-options
+ queue-threshold <0-65535>
+.. cfgcmd:: set firewall ipv6-name <name> rule <1-999999> log-options
+ queue-threshold <0-65535>
+
+ Define number of packets to queue inside the kernel before sending them to
+ userspace. Only applicable if rule log is enable and log group is defined.
+
.. cfgcmd:: set firewall name <name> rule <1-999999> disable
.. cfgcmd:: set firewall ipv6-name <name> rule <1-999999> disable