Re: Traffic monitoring
On Fri, Mar 14, 2003 at 10:39:59PM +0100, Christoph Moench-Tegeder wrote:
> If you are using kernel 2.4, you can use ulogd.
I never got ulogd running properly. I'm running 0.97-1 from woody, and
I was never able to get it to information to any files. Anyone want to
comment on the following ulogd.conf file?
nlgroup 1
logfile /var/log/ulogd.log
loglevel 1
plugin /usr/lib/ulogd/ulogd_BASE.so
syslogfile /var/log/ulogd.syslogemu
syslogsync 1
plugin /usr/lib/ulogd/ulogd_LOGEMU.so
dumpfile /var/log/ulogd.pktlog
And I've got a filewall rule:
-A INPUT -s 61.9.128.13 -i eth0 -p udp -m udp --dport 1024 -m limit --limit 20/hour -j ULOG --ulog-prefix BPA
(Checking with iptables-save -c reveals that the rule has been getting
matches).
Geoff Crompton
Reply to: