Visit Jeremy's Blog.
Go Back > Forums > Linux Forums > Linux - Security
User Name
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.


  Search this Thread
Old 10-14-2004, 04:54 AM   #1
Registered: Aug 2003
Location: Belgium
Distribution: -- Slackware for servers -- Debian for desktops --
Posts: 124

Rep: Reputation: 16
Iptables and logging

Hi all,

Im having problems logging iptables,

the rule i'm testing with :
LOG icmp -- anywhere anywhere LOG level debug

When I do all kinds of icmp stuff I can't seem to find any of them in my logs, i went to /var/log did a cat * and grepped on all sorts of stuff, nothing in these logs about iptables ...

I think it's my syslog.conf and the log-level (I can't find info bout' log level's as well).

can someone have a look at this and help me out ?

I also did following : dmesg -n 1

cause all my logs where popping up in my consoles...

root@Khufu:/var/log# cat /etc/syslog.conf
# /etc/syslog.conf Configuration file for syslogd.
# For more information see syslog.conf(5)
# manpage.

# First some standard logfiles. Log by facility.

auth,authpriv.* /var/log/auth.log
*.*;auth,authpriv.none -/var/log/syslog
#cron.* /var/log/cron.log
daemon.* -/var/log/daemon.log
kern.* -/var/log/kern.log
lpr.* -/var/log/lpr.log
mail.* -/var/log/mail.log
user.* -/var/log/user.log
uucp.* /var/log/uucp.log
# Emergencies are sent to everybody logged in.
*.emerg *
# Logging for the mail system. Split it up so that
# it is easy to write scripts to parse these files.
# -/var/log/
mail.warn -/var/log/mail.warn
mail.err /var/log/mail.err

# Logging for INN news system
news.crit /var/log/news/news.crit
news.err /var/log/news/news.err
news.notice -/var/log/news/news.notice

# Some `catch-all' logfiles.
news.none;mail.none -/var/log/debug
mail,news.none -/var/log/messages
# I like to have messages displayed on the console, but only on a virtual
# console I usually leave idle.
# news.=crit;news.=err;news.=notice;\
# *.=debug;*.=info;\
# *.=notice;*.=warn /dev/tty8

# The named pipe /dev/xconsole is for the `xconsole' utility. To use it,
# you must invoke `xconsole' with the `-file' option:
# $ xconsole -file /dev/xconsole [...]
# NOTE: adjust the list below, or you'll go crazy if you have a reasonably
# busy site..
*.=notice;*.=warn |/dev/xconsole

Could someone gimme some info about those log levels ? info, warn etc... ?

thx for having a look !
Old 10-18-2004, 12:40 AM   #2
Senior Member
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Since the iptables log messages are set at the debug log level, it looks like you should have them going to /var/log/debug as well as /var/log/kern.log. Anything in there? Keep in mind that iptables log messages don't actually say iptables in them, in fact they look like this:

Oct 18 01:35:23 hostname kernel: IN=eth0 OUT= MAC=00:30:4c:d0:42:49:10:0d:88:11:81:a4:08:00 SRC= DST= LEN=84 TOS=0x00 PREC=0x00 TTL=64 ID=

You might also want to remove debug from the list of log level priorities that are going to the console (see the last section of syslog.conf.


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
IPTABLES - Logging metallica1973 Linux - Security 10 10-27-2005 05:17 PM
iptables logging laotalax Linux - Networking 1 10-25-2005 09:55 AM
Logging for IPTABLES logo Linux - Networking 4 10-11-2004 09:23 AM
Iptables logging Mogwa_ Linux - Security 2 08-01-2004 02:54 PM
iptables and logging Yohhan Linux - Networking 2 05-04-2004 11:55 PM > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:47 PM.

Main Menu
Write for LQ is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration