IPTABLES, TCPDUMP LOGGING

From: cbielich (cbielich@yahoo.com)
Date: 10/03/02


From: cbielich@yahoo.com (cbielich)
Date: 3 Oct 2002 14:58:14 -0700

Current Setup:
I am running 2.4 Debian (Woody Dist) linux box as a router, NAT,
Firewall using iptables. I want to log constant traffic on both eth0
and eth1 on the same box. I have been messing around with tcpdump and
it is not really doing what I want. Maybe it can and I just cant get
it. Help me out!

I want to be able to write all traffic to a file that I can view later
on. But I want simple things like source and destination address from
the same packet. Tcpdump seems to only be able to capture on a per
interface basis which does not let me see the other interfaces
information. I went to tcpdump.org and the man is not helping. Does
anyone know a better solution then this or can I do it with tcpdump.

C



Relevant Pages

  • Re: IPTABLES, TCPDUMP LOGGING
    ... Tcpdump seems to only be able to capture on a per ... As an alternative you could always setup a couple of iptables rules to ... To log everything for eth0 for example you can do something like this ...
    (comp.os.linux.security)
  • Re: tcpdump and packets filtered by iptables
    ... >> Does tcpdump on an interface see the packets that are filtered out by ... > If you know your iptables then you know that only the ouput chain of any ...
    (comp.os.linux.networking)
  • Re: Network access fails unless tcpdump is running?
    ... I can not ping a remote host successfully unless I have "tcpdump -i ... eth0" running, in which case, my network access works fine. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: cvs problem with iptables
    ... > I have configured CVS on FC3.Now the problem is that if the iptables ... > but if the iptables is off then I can access it. ... Send in tcpdump ... tcpdump port 2401 and port 2402 ...
    (Fedora)
  • Network access fails unless tcpdump is running?
    ... I can not ping a remote host successfully unless I have "tcpdump -i ... eth0" running, in which case, my network access works fine. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)