How to log in LINUX IPTABLES
Before we get into the iptables rules, lets make sure that what we are doing is going to log.
First lets open up “/etc/syslog.conf” and add this entry
kern.* /var/log/firewall.log
Now restart your syslog daemon.. “/etc/init.d/syslog restart”
sudo iptables -I OUTPUT -j LOG
This means to jump to the LOG chain in iptables.
Now lets say you want your logging to be more verbose.
In iptables we can fix that by adding this entry in the rule.. –log-level 7.
This is the highest level of logging (DEBUG LEVEL).
e.g :
sudo iptables -I OUTPUT -j LOG –log-level 7
Logging
In the above examples none of the traffic will be logged.
If you would like to log dropped packets to syslog, this would be the quickest way:
iptables -I INPUT 5 -m limit –limit 5/min -j LOG –log-prefix “iptables denied: ” –log-level 7
iptables -I OUTPUT 5 -m limit –limit 5/min -j LOG –log-prefix “iptables denied: ” –log-level 7
To have packets Denied/Dropped, Place rule at the bottom of Chain or have
it modified for source/destination addresses.
iptables -A INPUT -j block
iptables -A OUTPUT -j block
Using Linux Gentoo:
sudo vi /syslog-ng/syslog-ng.conf
Add these lines :
source kernsrc { file(“/proc/kmsg”); };
destination kern { file(“/var/log/kern.log”); };
destination firewall { file(“/var/log/firewall.log”); };
filter f_firewall { match(“firewall”); };
filter f_kern { facility(kern) and not filter(f_firewall);};
log { source(kernsrc); filter(f_kern); destination(kern); };
log { source(kernsrc); filter(f_firewall); destination(firewall); };