iptablesã§ãã°ãåºåãã
ä¸é¨ã®éä¿¡ã®çéããã¾ãã§ããªãã£ãã®ã§ãiptablesã§ãã°ãåºåããå¿ è¦ããã£ãæã®ä½æ¥ã¡ã¢ã
ãããã¨
1.iptablesã§ãã°åºåè¨å®
2.syslog.confã®ãã°åºåå
è¨å®
3.ãã°ãã¡ã¤ã«ä½æ
4.syslogdã®åèµ·å
1.iptablesã§ãã°åºåè¨å®
iptables -A INPUT -j LOG --log-prefix "IPTABLES_INPUT_LOG : " --log-level=info
2.syslog.confã®ãã°åºåå è¨å®
vim /etc/syslog.conf # iptables log *kern.debug /var/log/iptables
ã¤ãã§ã«/var/log/messageã«iptablesã®ãã°åºããªãããã«ãã¨ã
åããsyslog.confå
ã®
ï¼.info;mail.none;news.none;authpriv.none;cron.none /var/log/messages
ãâã«å¤æ´ï¼kern.noneï¼ã®è¿½è¨
ï¼.info;mail.none;news.none;authpriv.none;cron.none;kern.none /var/log/messages
3.ãã°ãã¡ã¤ã«ä½æ
touch /var/log/iptables chmod 600 /var/log/iptables
4.syslogdã®åèµ·å
/etc/init.d/syslog restart
ããã§/var/log/iptablesã«ãã°ã§ãããã«ãªãã¾ãã
æ¤è¨¼ãçµäºããããã°åºåããªãã«ããã®ãå¿ããã«ãéä¿¡ãå¤ãç®æã ã¨ããã©ã¼ãã³ã¹ä¸ããã¾ãã
ã追è¨ã
iptablesã®è¨å®ãä¿åããå ´å
service iptables save