Re: iptables logs going to all ttys

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Mon, 2003-10-13 at 18:58, lucas wrote:
> Morning all,
> 
> I have the following in my firewall script, and to my knowledge this is 
> meant to stop all logs from going to all ttys but this is not the case 
> and its a real *pain* in the ass.
>
> $IPTABLES -N drop-and-log-it
> $IPTABLES -A drop-and-log-it -j LOG --log-level info
> $IPTABLES -A drop-and-log-it -j DROP
> 
> If someone could give me a hint as to what i have overlooked that would 
> be much appreciated, thanks

Syslog configuration is probably what you missed.  check
/etc/syslog.conf.  Very likely you have something like:
kern.*      /dev/console
in there, which states that all kernel messages of whatever level will
be sent to /dev/console.

For myself, I disable the /dev/console setting, then add:
kern.=debug  /var/log/firewall
kern.=warning /var/log/firewalladmin

Unless you're running a custom kernel with debugging enabled, the first
channel (debug) should be almost empty of traffic, ideal for redirection
to a firewall-only log file with "--log-level debug".  Everything of
level 'info' or higher usually goes to /var/log/messages as well.

j




[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux