diff --git a/sbin/ipfw/ipfw.8 b/sbin/ipfw/ipfw.8 index e2815fd86bf0..7fed2ba08b4d 100644 --- a/sbin/ipfw/ipfw.8 +++ b/sbin/ipfw/ipfw.8 @@ -1075,7 +1075,8 @@ There is one kind of packet that the firewall will always discard, that is a TCP packet's fragment with a fragment offset of one. This is a valid packet, but it only has one use, to try -to circumvent firewalls. When logging is enabled, these packets are +to circumvent firewalls. +When logging is enabled, these packets are reported as being dropped by rule -1. .It If you are logged in over a network, loading the