Mailing List ArchiveSupport open source code!
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]Re: tlug: ipchains logs and nmap audit
- To: tlug@example.com
- Subject: Re: tlug: ipchains logs and nmap audit
- From: Jim Tittsler <jwt-tlug@example.com>
- Date: Mon, 24 Jan 2000 10:39:05 +0900
- Content-Type: text/plain; charset=us-ascii
- In-Reply-To: <20000122075050.A10636@example.com>; from subb3@example.com on Sat, Jan 22, 2000 at 07:50:50AM -0500
- Organization: 7J1AJH/AI8A Tokyo
- References: <20000122075050.A10636@example.com>
- Reply-To: tlug@example.com
- Sender: owner-tlug@example.com
On Sat, Jan 22, 2000 at 07:50:50AM -0500, Subba Rao wrote: > I have several ipchain rules. One of them is: > > ipchains -A input -i ppp0 -p TCP --destination-port 21 -l -j DENY > > Why are these ipchains not doing any logging? I do have the -l option > invoked for logging. The packet is supposed to be denied at the IP level > and then logged into syslog. When I try to connect from another address to > the IP address of the ppp0 interface, nothing gets logged. Instead, the > tcplogd daemon captures it into the log. tcplogd is an application level > filter and not at IP level. Why is this ipchains rule (and others) not > getting logged? My guess would be that not only is it not being logged, the rule is not actually active or the packet wouldn't have made it farther up the stack. Does 'cat /proc/net/ip_fwnames /proc/net/ip_fwchains' suggest your rules have actually been applied? > How are you auditing your services on the ppp0 interface? What options in > ipchains are you using to do the logging? The -l switch causes a log message which klogd catches and hands off to syslogd. You'll want to make sure your /etc/syslogd.conf does whatever you think appropriate for messages with facility 'kernel' and level 'info'. -- Jim Tittsler, Tokyo ICQ: 5981586 -------------------------------------------------------------------- Next Nomikai Meeting: February 18 (Fri) 19:00 Tengu TokyoEkiMae Next Technical Meeting: March 11 (Sat) 13:00 Temple University Japan * Topic: TBD -------------------------------------------------------------------- more info: http://www.tlug.gr.jp Sponsor: Global Online Japan
- References:
- tlug: ipchains logs and nmap audit
- From: Subba Rao <subb3@example.com>
Home | Main Index | Thread Index
- Prev by Date: Re: tlug: Redhat version info
- Next by Date: Re: tlug: gtk and kinput2
- Prev by thread: tlug: ipchains logs and nmap audit
- Next by thread: tlug: J email from linux to Win98
- Index(es):
Home Page Mailing List Linux and Japan TLUG Members Links