Hi,
Found this
http://blog.shadypixel.com/log-iptab...-with-rsyslog/
And so have created
cat iptables.conf which has
Code:
:msg, startswith, "iptables denied: " -/var/log/iptables.log
& ~
However items are still getting logged to messages not /var/log/iptables.log
These are the iptables.rules being restored via iptables-restore - any ideas please?
Code:
# Generated by iptables-save v1.4.1.1 on Wed Jul 15 15:26:08 2009
*filter
:INPUT DROP [712:79941]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [142245:17267585]
:allowed - [0:0]
:existing-connections - [0:0]
-A INPUT -m limit --limit 5/min -j LOG --log-prefix "iptables denied: " --log-level 4
-A INPUT -j existing-connections
-A INPUT -j allowed
-A existing-connections -i lo -j ACCEPT
-A existing-connections -m state --state ESTABLISHED -j ACCEPT
-A existing-connections -m state --state RELATED -j ACCEPT
COMMIT
# Completed on Wed Jul 15 15:26:08 2009
# Generated by iptables-save v1.4.1.1 on Wed Jul 15 15:26:08 2009
*mangle
:PREROUTING ACCEPT [181100:209038881]
:INPUT ACCEPT [174949:207323062]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [142245:17267585]
:POSTROUTING ACCEPT [142254:17270190]
COMMIT
# Completed on Wed Jul 15 15:26:08 2009
Bookmarks