[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: firehol logging to console



On Wed, 28 Apr 2004, ankill@idssecure.org wrote:
> On Tue, Apr 27, 2004 at 07:26:52PM +0200, Jonas Meurer a écrit :
>> After successfully setting up firehol, i get a log message to the
>> console i'm currently reading every time a remote machine tries to
>> connect my system. The log looks similar to:
>> IN-internet:IN=ppp0 OUT= MAC= SRC=62.75.128.97 DST=217.233.195.51 \
>>       LEN=40 TOS=0x00 PREC=0x00 TTL=52 ID=48754 PROTO=TCP SPT=59028 \
>>       DPT=321 WINDOW=3072 RES=0x00 SYN URGP=0
>> 
>> internet is the device name in firehol.conf and ppp0 is the interface
>> connected to the internet. Generally, there is no problem with the
>> log message, but in my opinion it would be somehow better to redirect
>> it to a firehol logfile, don't you think so?
>>
> hey, do you know an iptables' match who is called ulog ??

Just as a note, you can specify (in your firehol.conf) file:

FIREHOL_LOG_MODE="ULOG"

That will activate the ULOG target rather than the LOG target within
firehol.

Check the bottom of the 'commands' section of the documentation for
other relevant variables.

      Daniel

-- 
There is no happiness in having or in getting, but only in giving.
        -- Henry Drummond



Reply to: