[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Traffic monitoring



On Fri, Mar 14, 2003 at 10:39:59PM +0100, Christoph Moench-Tegeder wrote:
> If you are using kernel 2.4, you can use ulogd.

  I never got ulogd running properly. I'm running 0.97-1 from woody, and
  I was never able to get it to information to any files. Anyone want to
  comment on the following ulogd.conf file?

nlgroup 1
logfile /var/log/ulogd.log
loglevel 1
plugin /usr/lib/ulogd/ulogd_BASE.so
syslogfile /var/log/ulogd.syslogemu
syslogsync 1
plugin /usr/lib/ulogd/ulogd_LOGEMU.so
dumpfile /var/log/ulogd.pktlog


  And I've got a filewall rule:
-A INPUT -s 61.9.128.13 -i eth0 -p udp -m udp --dport 1024 -m limit --limit 20/hour -j ULOG --ulog-prefix BPA 

  (Checking with iptables-save -c reveals that the rule has been getting
  matches).

  Geoff Crompton



Reply to: