Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
iptables logging
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
ee99ee2
Guru
Guru


Joined: 18 Jun 2002
Posts: 307
Location: Murfreesboro, TN, USA

PostPosted: Thu Oct 23, 2003 9:46 am    Post subject: iptables logging Reply with quote

Is there a way to have iptables log to something like /var/log/iptables? I know syslog is what does it, but is something like that possiable? I dunno much about the workings of syslog...

-ee99ee
_________________
ServerMotion
Back to top
View user's profile Send private message
magnet
Guru
Guru


Joined: 16 Mar 2003
Posts: 582
Location: france

PostPosted: Thu Oct 23, 2003 10:05 am    Post subject: Reply with quote

hello.

to log things with iptables, you'll need a kernel module ( CONFIG_IP_NF_TARGET_LOG ).
option related to logs are :

--log-prefix , to specify a prefix for data in the logs
--log-level , log's verbosity

a short exemple, how to log things that you DROP.
let's create a new chain :
Code:

iptables -N LOG_DROP 

now log things that we drop :
Code:

iptables -A LOG_DROP -j LOG --log-prefix '[DROPPED] : '

then drop things that we drop :p
Code:

iptables -A LOG_DROP -j DROP


now don t forget to use LOG_DROP instead of DROP.like
Code:

iptables -A FORWARD -j LOG_DROP
iptables -A INPUT -j LOG_DROP
iptables -A OUTPUT -j LOG_DROP

_________________
every step aim at glory.
Back to top
View user's profile Send private message
nephros
Advocate
Advocate


Joined: 07 Feb 2003
Posts: 2139
Location: Graz, Austria (Europe - no kangaroos.)

PostPosted: Thu Oct 23, 2003 11:14 am    Post subject: Reply with quote

I think he meant how to log into a specified file instead of the syslog rather than how to log at all.
Isn't that what ULOG is for?
from the kernel help:
Quote:
CONFIG_IP_NF_TARGET_ULOG: This option adds a `ULOG' target, which allows ou to create rules in any iptables table. The packet is passed to a userspace logging daemon using netlink multicast sockets; unlike the LOG target whch can only be viewed through syslog.
The apropriate userspace logging daemon (ulogd) may be obtained from http://www.gnumonks.org/projects/ulogd

I never played with this though.
_________________
Please put [SOLVED] in your topic if you are a moron.
Back to top
View user's profile Send private message
magnet
Guru
Guru


Joined: 16 Mar 2003
Posts: 582
Location: france

PostPosted: Thu Oct 23, 2003 12:19 pm    Post subject: Reply with quote

oh 8O

I shouldn t answer early in the morning !
_________________
every step aim at glory.
Back to top
View user's profile Send private message
ee99ee2
Guru
Guru


Joined: 18 Jun 2002
Posts: 307
Location: Murfreesboro, TN, USA

PostPosted: Thu Dec 11, 2003 7:24 am    Post subject: Reply with quote

Both answeres answered questions I had. Thanks!

-ee99ee
_________________
ServerMotion
Back to top
View user's profile Send private message
ikaro
Advocate
Advocate


Joined: 14 Jul 2003
Posts: 2527
Location: Denmark

PostPosted: Thu Dec 11, 2003 8:56 am    Post subject: Reply with quote

I use ULOG with shorewall, and its great.
Easy to setup too.
_________________
linux: #232767
Back to top
View user's profile Send private message
b0fh
Guru
Guru


Joined: 16 Jun 2003
Posts: 426

PostPosted: Fri Dec 26, 2003 6:26 pm    Post subject: Reply with quote

Yep, ulogd works nice, although I get masses of data :(
My mysql.log now reached nice 1,9GB because of ulogd inserting so much stuff... How can I prevent mysql to log every ulog event? Or would it be easier to simply wipe the log once a week?
Back to top
View user's profile Send private message
ikaro
Advocate
Advocate


Joined: 14 Jul 2003
Posts: 2527
Location: Denmark

PostPosted: Fri Dec 26, 2003 7:14 pm    Post subject: Reply with quote

ULOGD only logs the stuff you send at it.
you can 1) dont actiavete so much logs to be sent to ulogd, 2) cron to wipe the log once a week , like you sugested, evt, gzip the old log, make a newone, and next week wipe the gziped etc..etc.., just in case you need to go back and check something on the last weeks log.
_________________
linux: #232767
Back to top
View user's profile Send private message
b0fh
Guru
Guru


Joined: 16 Jun 2003
Posts: 426

PostPosted: Fri Dec 26, 2003 7:19 pm    Post subject: Reply with quote

I'm trying to cycle logfiles via cron and savelog. But which signal does mysqld need to re-cycle it's logs? killall -HUP seems not to work.
Back to top
View user's profile Send private message
ikaro
Advocate
Advocate


Joined: 14 Jul 2003
Posts: 2527
Location: Denmark

PostPosted: Fri Dec 26, 2003 9:11 pm    Post subject: Reply with quote

im affraid i cant help you with mysql, my setup is with plain files.
sorry.
_________________
linux: #232767
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum