Networking Forums

Networking Forums > Computer Networking > Linux Networking > iptables and logging [newbie]

Reply
Thread Tools Display Modes

iptables and logging [newbie]

 
 
Madhur Ahuja
Guest
Posts: n/a

 
      10-08-2004, 06:14 PM
Hello
I was trying to set up iptables on my RH 9.0 and enable logging
for the rejected packets in a file. However the log is also being
delivered to the console i.e. /dev/tty. Here is my setup(just for test)

iptables --list >
Chain INPUT (policy ACCEPT)
target prot opt source destination
LOG all -- localhost.localdomain localhost.localdomainLOG level
warning
REJECT all -- localhost.localdomain localhost.localdomainreject-with
icmp-port-unreachable

Chain FORWARD (policy ACCEPT)
target prot opt source destination

Chain OUTPUT (policy ACCEPT)
target prot opt source destination

and syslog.conf>

# Log all kernel messages to the console.
# Logging much else clutters up the screen.
kern.err /var/log/iptables
kern.* /var/log/kernel

# Log anything (except mail) of level info or higher.
# Don't log private authentication messages!
*.info;local0.!info;mail.none;authpriv.none;cron.n one /var/log/messages

# The authpriv file has restricted access.
authpriv.* /var/log/secure

# Log all the mail messages in one place.
mail.* /var/log/maillog


# Log cron stuff
cron.* /var/log/cron

# Everybody gets emergency messages
#*.emerg *

# Save news errors of level crit and higher in a special file.
uucp,news.crit /var/log/spooler

# Save boot messages also to boot.log
local7.* /var/log/boot.log

#madhur ahuja created network log
#local0.error /dev/console
local0.* /var/log/madhur



--
Madhur Ahuja [madhur<underscore>ahuja<at>yahoo<dot>com]

Homepage
http://madhur.netfirms.com






 
Reply With Quote
 
 
 
 
tibo
Guest
Posts: n/a

 
      10-08-2004, 08:13 PM

"Madhur Ahuja" <(E-Mail Removed)> a écrit dans le message de news:
(E-Mail Removed)...
> Hello
> I was trying to set up iptables on my RH 9.0 and enable logging
> for the rejected packets in a file. However the log is also being
> delivered to the console i.e. /dev/tty. Here is my setup(just for test)
>
> iptables --list >
> Chain INPUT (policy ACCEPT)
> target prot opt source destination
> LOG all -- localhost.localdomain localhost.localdomainLOG level
> warning
> REJECT all -- localhost.localdomain
> localhost.localdomainreject-with
> icmp-port-unreachable
>
> Chain FORWARD (policy ACCEPT)
> target prot opt source destination
>
> Chain OUTPUT (policy ACCEPT)
> target prot opt source destination
>
> and syslog.conf>
>
> # Log all kernel messages to the console.
> # Logging much else clutters up the screen.
> kern.err /var/log/iptables
> kern.* /var/log/kernel
>
> # Log anything (except mail) of level info or higher.
> # Don't log private authentication messages!
> *.info;local0.!info;mail.none;authpriv.none;cron.n one /var/log/messages
>
> # The authpriv file has restricted access.
> authpriv.* /var/log/secure
>
> # Log all the mail messages in one place.
> mail.* /var/log/maillog
>
>
> # Log cron stuff
> cron.* /var/log/cron
>
> # Everybody gets emergency messages
> #*.emerg *
>
> # Save news errors of level crit and higher in a special file.
> uucp,news.crit /var/log/spooler
>
> # Save boot messages also to boot.log
> local7.* /var/log/boot.log
>
> #madhur ahuja created network log
> #local0.error /dev/console
> local0.* /var/log/madhur
>


Good.

Where is your question ?


>
> --
> Madhur Ahuja [madhur<underscore>ahuja<at>yahoo<dot>com]
>
> Homepage
> http://madhur.netfirms.com
>
>
>
>
>
>



 
Reply With Quote
 
Madhur Ahuja
Guest
Posts: n/a

 
      10-08-2004, 09:24 PM
tibo <(E-Mail Removed)> wrote:
> "Madhur Ahuja" <(E-Mail Removed)> a écrit dans le message de news:
> (E-Mail Removed)...
> Good.
>
> Where is your question ?
>
>


Sorry, my question is how can I supress the output to console.
I want the output in the file /var/log/iptables. I have not specified
console in /etc/syslog.conf.

What is the standard way of getting log from iptables only, not kernel
messages.

--
Madhur Ahuja [madhur<underscore>ahuja<at>yahoo<dot>com]

Homepage
http://madhur.netfirms.com






 
Reply With Quote
 
Tim Rhodes
Guest
Posts: n/a

 
      10-11-2004, 05:08 PM
In comp.os.linux.security Madhur Ahuja <(E-Mail Removed)> wrote:
> Sorry, my question is how can I supress the output to console.
> I want the output in the file /var/log/iptables. I have not specified
> console in /etc/syslog.conf.
>
> What is the standard way of getting log from iptables only, not kernel
> messages.

This is caused by the default log-level of iptables (kernel generated
logged messages) and the klogd daemon default log level. I can't recall
what the klogd default is, but you can raise it with the '-c' option in
it's startup script or (better solution), add '--log-level 7' to your
iptable rule.
--
... Tim Rhodes ........................ http://rhodes.cc.vt.edu/~rhodes ..
... NIS-Systems Support, Virginia Tech .............. (E-Mail Removed) ..
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
IPtables logging failure (multiple NICs) 3strands@gmail.com Linux Networking 2 03-14-2006 03:23 AM
iptables - newbie explodingGo4@gmail.com Linux Networking 5 01-11-2006 03:32 AM
User logging (Newbie) PDub Windows Networking 2 06-13-2005 06:03 PM
iptables logging sam Linux Networking 1 10-29-2003 06:45 AM
IPTables Logging problem Colin Bigam Linux Networking 1 07-22-2003 03:29 PM



1 2 3 4 5 6 7 8 9 10 11