: 28 czerwca 2006, 21:56
To może już lepiej zrobić użytek z conntracka, albo z -j LOG ? A w ogóle jeśli mowa o iptables i logowaniu, to najlepszym narzędziem do tego jest specter (tudzież ulogd, acz specter jest nieco bardziej rozwinięty).
Kod: Zaznacz cały
# apt-cache show specter
Description: packet logger for netfilter's ULOG target
specter is a userspace logging facility for Linux. It uses netfilter
ULOG target for packets gathering, and then passes them to attached
plugins. Modularized structure makes specter very flexible and robust.
It's based on ulogd, but has improved design and wider functionality.
.
Plugins:
- EXEC plugin that executes given commands when specified packet is received
- HTTP plugin that parses http traffic
- PWSNIFF plugin that logs plaintext passwords as used with FTP and POP3
- OPRINT simple output module, dumping specified packets to file
- Logging plugins that emulate few logging facilities
- mysql and postgresql extensions available via separate packages
.
Homepage: [url]http://joker.linuxstuff.pl/specter/[/url]
Tag: admin::logging, interface::daemon, role::sw:server, security::firewall, use::monitor