Solved

IPTables Log Files

Posted on 2006-11-16
3
240 Views
Last Modified: 2010-03-17
In IP-tables I have the following rules

-A FORWARD -o eth0 -j LOG --log-level 7 --log-prefix BANDWIDTH_OUT:
-A FORWARD -i eth0 -j LOG --log-level 7 --log-prefix BANDWIDTH_IN:
-A OUTPUT -o eth0 -j LOG --log-level 7 --log-prefix BANDWIDTH_OUT:
-A INPUT -i eth0 -j LOG --log-level 7 --log-prefix BANDWIDTH_IN:

These are the rules which create the log files. Do you know what log-level 7 does and what are the other log levels?  I want to modify this rule so that it will log accepted packets instead of dropped packets but I have not had any luck finding out how to do this.  
0
Comment
Question by:MarkWP
  • 2
3 Comments
 
LVL 43

Assisted Solution

by:ravenpl
ravenpl earned 500 total points
ID: 17959191
#define LOG_EMERG       0       /* system is unusable */
#define LOG_ALERT       1       /* action must be taken immediately */
#define LOG_CRIT        2       /* critical conditions */
#define LOG_ERR         3       /* error conditions */
#define LOG_WARNING     4       /* warning conditions */
#define LOG_NOTICE      5       /* normal but significant condition */
#define LOG_INFO        6       /* informational */
#define LOG_DEBUG       7       /* debug-level messages */
Hope it;s clear
0
 
LVL 43

Accepted Solution

by:
ravenpl earned 500 total points
ID: 17959256
> I want to modify this rule so that it will log accepted packets instead of dropped packets but I have not had any luck finding out how to do this.
the LOG target just logs the packet, then next rule is beeing matched. So I assume there is next rule that DROPS the packet, or chain policy is set to DROP.
If You want LOG accepted packets, then try creating new chain like
iptables -N logok
iptables -A logok -j LOG
iptables -A logok -j ACCEPT

then instead of ACCEPTING some packets, redirect them to logok chain. Eg. currently You have
iptables -A INPUT -i lo -j ACCEPT # change to
iptables -A INPUT -i lo -j logok

If You bring here full iptables configuration, it's going to be easier.
0
 
LVL 1

Author Comment

by:MarkWP
ID: 17966580
-A FORWARD -j LOG --log-prefix "Accepted: " worked. Thanks for the help!
0

Featured Post

Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have seen several blogs and forum entries elsewhere state that because NTFS volumes do not support linux ownership or permissions, they cannot be used for anonymous ftp upload through the vsftpd program.   IT can be done and here's how to get i…
Note: for this to work properly you need to use a Cross-Over network cable. 1. Connect both servers S1 and S2 on the second network slots respectively. Note that you can use the 1st slots but usually these would be occupied by the Service Provide…
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…
In a recent question (https://www.experts-exchange.com/questions/29004105/Run-AutoHotkey-script-directly-from-Notepad.html) here at Experts Exchange, a member asked how to run an AutoHotkey script (.AHK) directly from Notepad++ (aka NPP). This video…

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question