Re: IPTables Upgrade

From: Phil Gregory (phil_g@pobox.com)
Date: 07/23/01


Date: Mon, 23 Jul 2001 12:21:18 -0400
From: Phil Gregory <phil_g@pobox.com>
To: "'focus-linux@securityfocus.com'" <focus-linux@securityfocus.com>
Subject: Re: IPTables Upgrade
Message-ID: <20010723122118.J16388@mithrandir.geeksimplex.org>

On Sun, Jul 22, 2001 at 05:13:11AM -0700, Brian Kejser wrote:
> I recently upgraded my ipchains firewall to iptables and I need to parse my
> log files on a daily basis to look for unusual activity. I could write the
> script myself but it would be very basic. Does anyone know of a parsing tool
> for iptable logs? I used to use pflap for ipchains.

I use fwlogwatch (<http://www.kyb.uni-stuttgart.de/boris/software.shtml>)
for my ipfilter logs. It claims to support "Linux ipchains, Linux
netfilter/iptables, Solaris/BSD ipfilter, Cisco IOS and Cisco PIX".

-- 
phil_g@pobox.com / DNRC / UMBC-LUG: http://linux.umbc.edu
PGP public key fingerprint:  0A7D B3AD 2D10 1099  7649 AB64 04C2 05A6
--- --
  "What guarantees will you give me that the crews will not open fire on a
Centauri vessel as it approaches Babylon 5?"
  "It's the same guarantee I gave when I said that none of the other Narns
would break into your quarters in the middle of the night and slit your
throat."
  "Mr. Garibaldi, you have never given me that promise."
  "You're right.  Sleep tight."
                       --Londo and Garibaldi (Babylon 5, "Walkabout")
---- --- --



Relevant Pages

  • Re: When not to log
    ... >>> Why do you persist in saying they're scanning you? ... I got logs here over the ... mails root every tenth iptables 'hit' with a summary!. ... >> So if this hastle persists I think I'll just remove IPtables. ...
    (comp.os.linux.security)
  • Re: Prevent access to linux server when mac adress does not match ip adress
    ... Iptables has much more features than ipchain. ... Prior to the 2.2.x kernel, the firewall was controlled by "ipfwadm". ... introduced the IPCHAINS tool to control that. ... Often the upgrade is too big and bulky for the older ...
    (comp.os.linux.networking)
  • Re: IPChains with RH 9? "Protocol not available"
    ... Yes, iptables is way more versatile than ipchains, and ipchains ... is no longer supported in the redhat kernel by default. ... is RH 9 stock kernel still support ipchains? ...
    (RedHat)
  • Re: A Question On Ipchains Input Rules
    ... If RH72 allows using iptables instead of ipchains, ... return packets for any established connections, ... outbound SMTP sessions, you just allow outbound SMTP, and the ...
    (comp.os.linux.security)
  • Re: Layering portsentry and ipchains
    ... >> PortSentry well iptables notice a system scanning ports on your ... Appart from ssh, I allow only related/established. ... >> list of trusted sites, and you can always manually overide the block. ... rather than running off the logs would be preferable. ...
    (comp.os.linux.security)