Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

IPTables Log Files

Posted on 2006-11-16
3
Medium Priority
?
245 Views
Last Modified: 2010-03-17
In IP-tables I have the following rules

-A FORWARD -o eth0 -j LOG --log-level 7 --log-prefix BANDWIDTH_OUT:
-A FORWARD -i eth0 -j LOG --log-level 7 --log-prefix BANDWIDTH_IN:
-A OUTPUT -o eth0 -j LOG --log-level 7 --log-prefix BANDWIDTH_OUT:
-A INPUT -i eth0 -j LOG --log-level 7 --log-prefix BANDWIDTH_IN:

These are the rules which create the log files. Do you know what log-level 7 does and what are the other log levels?  I want to modify this rule so that it will log accepted packets instead of dropped packets but I have not had any luck finding out how to do this.  
0
Comment
Question by:MarkWP
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 43

Assisted Solution

by:ravenpl
ravenpl earned 2000 total points
ID: 17959191
#define LOG_EMERG       0       /* system is unusable */
#define LOG_ALERT       1       /* action must be taken immediately */
#define LOG_CRIT        2       /* critical conditions */
#define LOG_ERR         3       /* error conditions */
#define LOG_WARNING     4       /* warning conditions */
#define LOG_NOTICE      5       /* normal but significant condition */
#define LOG_INFO        6       /* informational */
#define LOG_DEBUG       7       /* debug-level messages */
Hope it;s clear
0
 
LVL 43

Accepted Solution

by:
ravenpl earned 2000 total points
ID: 17959256
> I want to modify this rule so that it will log accepted packets instead of dropped packets but I have not had any luck finding out how to do this.
the LOG target just logs the packet, then next rule is beeing matched. So I assume there is next rule that DROPS the packet, or chain policy is set to DROP.
If You want LOG accepted packets, then try creating new chain like
iptables -N logok
iptables -A logok -j LOG
iptables -A logok -j ACCEPT

then instead of ACCEPTING some packets, redirect them to logok chain. Eg. currently You have
iptables -A INPUT -i lo -j ACCEPT # change to
iptables -A INPUT -i lo -j logok

If You bring here full iptables configuration, it's going to be easier.
0
 
LVL 1

Author Comment

by:MarkWP
ID: 17966580
-A FORWARD -j LOG --log-prefix "Accepted: " worked. Thanks for the help!
0

Featured Post

Hire Technology Freelancers with Gigs

Work with freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely, and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have seen several blogs and forum entries elsewhere state that because NTFS volumes do not support linux ownership or permissions, they cannot be used for anonymous ftp upload through the vsftpd program.   IT can be done and here's how to get i…
Note: for this to work properly you need to use a Cross-Over network cable. 1. Connect both servers S1 and S2 on the second network slots respectively. Note that you can use the 1st slots but usually these would be occupied by the Service Provide…
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
Visualize your data even better in Access queries. Given a date and a value, this lesson shows how to compare that value with the previous value, calculate the difference, and display a circle if the value is the same, an up triangle if it increased…
Suggested Courses

604 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question