How to log in LINUX IPTABLES

Before we get into the iptables rules, lets make sure that what we are doing is going to log.
First lets open up “/etc/syslog.conf” and add this entry

kern.* /var/log/firewall.log

Now restart your syslog daemon.. “/etc/init.d/syslog restart”

sudo iptables -I OUTPUT -j LOG
This means to jump to the LOG chain in iptables.
Now lets say you want your logging to be more verbose.
In iptables we can fix that by adding this entry in the rule.. –log-level 7.
This is the highest level of logging (DEBUG LEVEL).

e.g :

sudo iptables -I OUTPUT -j LOG –log-level 7

Logging

In the  above examples none of the traffic will be logged.
If you would like to log dropped packets to syslog, this would be the quickest way:

iptables -I INPUT 5 -m limit –limit 5/min -j LOG –log-prefix “iptables denied: ” –log-level 7
iptables -I OUTPUT 5 -m limit –limit 5/min -j LOG –log-prefix “iptables denied: ” –log-level 7

To have packets Denied/Dropped, Place rule at the bottom of Chain or have
it modified for source/destination addresses.

iptables -A INPUT -j block
iptables -A OUTPUT -j block

Using Linux Gentoo:

sudo vi /syslog-ng/syslog-ng.conf

Add these lines :

source kernsrc { file(“/proc/kmsg”); };
destination kern { file(“/var/log/kern.log”); };
destination firewall { file(“/var/log/firewall.log”); };
filter f_firewall { match(“firewall”); };
filter f_kern { facility(kern) and not filter(f_firewall);};
log { source(kernsrc); filter(f_kern); destination(kern); };
log { source(kernsrc); filter(f_firewall); destination(firewall); };