LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 12-26-2005, 12:51 PM   #1
LiNuXkOlOnIe
Member
 
Registered: Dec 2005
Location: North germany
Distribution: Linux Mint
Posts: 46

Rep: Reputation: 16
Question iptable messages in logfile for blocked requests to my ip adress


Hallo, i have no server but Fedora 3 as Desktop. Of course with the iptable firewall which i configure with fwbuilder. Now what i want to know is where can i find the messages which accesses to my pc were tried ? On which port/protocol etc. It's only for me to know if anything goes broken (virus etc.) The portscan is very well i made at an online web-site which offers port-scan service.
I thought all messages will be logged to syslog ? Nothin in there.

Thank you.
 
Old 12-26-2005, 03:13 PM   #2
wrj
Member
 
Registered: Aug 2003
Location: Canada/US
Distribution: Ubuntu, Arch
Posts: 84

Rep: Reputation: 15
Check your /etc/syslog.conf file. You should have an entry in there that tells you how your kernel logs are set up.

Mine is:
kern.* -/var/log/kern.log

Hope that helps.
 
Old 12-27-2005, 09:22 AM   #3
LiNuXkOlOnIe
Member
 
Registered: Dec 2005
Location: North germany
Distribution: Linux Mint
Posts: 46

Original Poster
Rep: Reputation: 16
Thumbs up

This is my entry: I never thought that this would be. This confuses me a little. Thank you a lot. This will me help further.



Code:
# Log all kernel messages to the console.
# Logging much else clutters up the screen.
#kern.*                                                 /dev/console
I added the line you wrote:

Code:
kern.* -/var/log/kern.log
but there are no entries. ???

Last edited by LiNuXkOlOnIe; 12-27-2005 at 10:03 AM.
 
Old 12-27-2005, 10:36 AM   #4
doublejoon
Member
 
Registered: Oct 2003
Location: King George, VA
Distribution: RHEL/CentOS/Scientific/Fedora, LinuxMint
Posts: 370

Rep: Reputation: 44
Restart syslog
 
Old 12-27-2005, 12:40 PM   #5
wrj
Member
 
Registered: Aug 2003
Location: Canada/US
Distribution: Ubuntu, Arch
Posts: 84

Rep: Reputation: 15
Yes, restart syslogd. Also, try reading through the man pages for syslog.conf for a better explanation of how it works.

"man syslog.conf"
 
Old 12-27-2005, 04:11 PM   #6
LiNuXkOlOnIe
Member
 
Registered: Dec 2005
Location: North germany
Distribution: Linux Mint
Posts: 46

Original Poster
Rep: Reputation: 16
Post Thanx.

It works. But the result is not what i expected. The system/kernel-logs were already logged in messages and bootmessages.

I read the man-page after i read the first post to understand what the cryptic line means. Now give me another hint and explain me where
i can log or find the ip adresses which wanted to access my pc sniffing etc. Let me compare to ZoneAlarm. There is always a list/log where you can look at if someone tried to breach your pc. port/protocol. Does iptables log something in the same way ?
I have installed snort too. Iam still reading. I think this one does something similar and can be linked to iptables so that snort does the work. Which is not what i want right now. It's only an where is the message if there is one from iptables.

Thank you.

 
Old 12-28-2005, 05:13 AM   #7
Notwerk
Member
 
Registered: Apr 2005
Location: Jordan
Distribution: Debian (Sarge), Ubuntu (6.06)
Posts: 271

Rep: Reputation: 31
Check $man iptables
for MATCH EXTENSIONS.

Be aware that you'll need to use TWO rules for every packet you reject/drop if you want to log it. One to log it and a second to drop it. You can also define the log level there.
 
Old 12-29-2005, 01:52 PM   #8
LiNuXkOlOnIe
Member
 
Registered: Dec 2005
Location: North germany
Distribution: Linux Mint
Posts: 46

Original Poster
Rep: Reputation: 16
Thank you. I think you mean LOG. Am i right. This should work. I try to setup a rule with fwbuilder. I am on it.

cu

Uuups. Why didn't i looked in fwbuilder already ? There is already a option for logging. Anyway... thanx again.

Last edited by LiNuXkOlOnIe; 12-29-2005 at 02:47 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Shell scripting: Print output to logfile, error to logfile & screen stefanlasiewski Programming 18 05-22-2008 12:47 PM
pam_unix in logfile jkmartha Linux - Newbie 1 05-04-2005 09:40 PM
logfile analyse saavik Linux - Networking 4 03-30-2005 05:14 AM
Startup Logfile Wynand1 Linux - Newbie 1 06-01-2004 06:04 AM
I am looking for a LogFile Viewer dude4you Linux - Software 6 02-02-2004 04:09 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 04:21 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration