Re: How to read firewall logs?

From: Erik (et57)
Date: 07/31/04


Date: Sat, 31 Jul 2004 14:38:39 +0200

On Fri, 04 Jun 2004 13:04:07 -0500, the right honourable Mike Oliver
<mike_lists@verizon.net> wrote:

>OK, so I finally got around to having iptables LOG and then DROP
>uninvited input packets, rather than just DROPping them. I didn't
>expect the volume to be quite that high! Seems people are attacking --
>or at least sending SYN packets -- every few seconds.
>
>How do I figure out just what is being attempted? I can trace
>the SRC field with the "host" command, but what are TTL, ID,
>SPT, DPT, WINDOW, URGP? Googling on these terms brings up
>a lot of logs; didn't see any direct explanation. Can I tell
>if these are attempts to establish, say, telnet, ftp, rsh, or
>ssh connections?

OOOOOOOOW... you need to read/study Andreasson's manual:

http://iptables-tutorial.frozentux.net/iptables-tutorial.html

Really, if you want to read logs, you need to feel at home in this
material. There are no shortcuts.

After that, look at http://www.snort.org/

frgr
Erik



Relevant Pages

  • Re: deadlock with 2.6.9
    ... this time not related to burning a dvd. ... Call Trace: ... logs to a stripe of two mirrors, ...
    (Linux-Kernel)
  • DBD::Pg 1.31 under mod_perl
    ... On Wed, 2003-11-19 at 18:01, Rudy Lippan wrote: ... and Apache/mod_perl suddently dies without any trace of error in ... the logs. ...
    (perl.dbi.users)
  • Re: Login Failure
    ... Turn on your SQL Server Profiler, make sure you select the hostname or ... clientname as one of the columns in your trace and then start your trace on ... me about where the request is coming from (event logs/sql logs) ...
    (microsoft.public.sqlserver.security)
  • Re: Login Failure
    ... we'll see what that spits out for me. ... clientname as one of the columns in your trace and then start your trace ... tell me about where the request is coming from (event logs/sql logs) ...
    (microsoft.public.sqlserver.security)
  • Re: Problems on Linux power-up
    ... no trace of problems in logs, I am going to replace both the disks and the ... Alan Pritchard ...
    (comp.databases.pick)