Monitoring ipfw dynamic rules with Cacti & net-snmp
June 20th, 2005You'll need a fairly recent install of net-snmp for this, as it uses the 'extend' MIB.
# so we can track dynamic-rule count extend fw-dyn-rules /usr/local/bin/snmp-fw-dynrules
#!/bin/sh sysctl -n net.inet.ip.fw.dyn_count sysctl -n net.inet.ip.fw.dyn_max
- Current rules:
- Maximum rules:
Here's an export from our cacti install, which should include all of that.