why incoming packet's device not logging?
cranium2003
cranium2003 at yahoo.com
Sat May 21 09:04:46 CEST 2005
hello,
I added 3 rules to iptables as
iptables -A INPUT -j LOG
iptables -A OUTPUT -j LOG
iptables -A FORWARD -j LOG
But i am getting log of forward and output chain
correctly but why when packet comes its incoming
device is not logged. My IPTABLES is
# Generated by iptables-save v1.2.7a on Sat May 21
12:34:30 2005
*nat
:PREROUTING ACCEPT [123:21369]
:POSTROUTING ACCEPT [6:360]
:OUTPUT ACCEPT [6:360]
-A POSTROUTING -o eth0 -p icmp -j SNAT --to-source
10.1.1.1
COMMIT
# Completed on Sat May 21 12:34:30 2005
# Generated by iptables-save v1.2.7a on Sat May 21
12:34:30 2005
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [54:8496]
:RH-Lokkit-0-50-INPUT - [0:0]
-A INPUT -j RH-Lokkit-0-50-INPUT
-A INPUT -j LOG
-A FORWARD -j RH-Lokkit-0-50-INPUT
-A FORWARD -i eth0 -o eth1 -m state --state
RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i eth1 -o eth0 -m state --state
RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -j LOG
-A OUTPUT -j LOG
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 25
--tcp-flags SYN,RST,ACK SYN -j ACCEPT
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 80
--tcp-flags SYN,RST,ACK SYN -j ACCEPT
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 21
--tcp-flags SYN,RST,ACK SYN -j ACCEPT
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 22
--tcp-flags SYN,RST,ACK SYN -j ACCEPT
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 23
--tcp-flags SYN,RST,ACK SYN -j ACCEPT
-A RH-Lokkit-0-50-INPUT -i eth0 -p udp -m udp --sport
67:68 --dport 67:68 -j ACCEPT
-A RH-Lokkit-0-50-INPUT -i eth1 -p udp -m udp --sport
67:68 --dport 67:68 -j ACCEPT
-A RH-Lokkit-0-50-INPUT -i lo -j ACCEPT
-A RH-Lokkit-0-50-INPUT -i eth0 -j ACCEPT
-A RH-Lokkit-0-50-INPUT -i eth1 -j ACCEPT
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 0:1023
--tcp-flags SYN,RST,ACK SYN -j REJECT --reject-with
icmp-port-unreachable
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 2049
--tcp-flags SYN,RST,ACK SYN -j REJECT --reject-with
icmp-port-unreachable
-A RH-Lokkit-0-50-INPUT -p udp -m udp --dport 0:1023
-j REJECT --reject-with icmp-port-unreachable
-A RH-Lokkit-0-50-INPUT -p udp -m udp --dport 2049 -j
REJECT --reject-with icmp-port-unreachable
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport
6000:6009 --tcp-flags SYN,RST,ACK SYN -j REJECT
--reject-with icmp-port-unreachable
-A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 7100
--tcp-flags SYN,RST,ACK SYN -j REJECT --reject-with
icmp-port-unreachable
COMMIT
# Completed on Sat May 21 12:34:30 2005
__________________________________
Yahoo! Mail Mobile
Take Yahoo! Mail with you! Check email on your mobile phone.
http://mobile.yahoo.com/learn/mail
More information about the netfilter-devel
mailing list