Re: [suse-security] SuSE personal firewall in 7.3
As newbie and not well know in Linux I use SuSE 7.3 prof. with SuSE personal Firewall. From the, by me, well know Windows-os I use severall firewalls on different pc's. What strikes me is that I have on these Windows-machines allways a easy to read logfile of the firewall.
Take a look at /etc/syslog.conf where you can see which logfiles are configured for "sytem"-logs an your machine
To be more precise and newbie compliant /var/log/messages logfile for system wide logging /var/log/firewall logfile for firewall specific logs
This is something I cannot find on my Linux-machine. I went thru severall logfiles but cannot find anything that says something like : access denied, blocked, refused .... together with ip-addresses and so on.
You have to set the level of logging in the configuration file of your firewall like this /etc/rc.config.d/firewall.rc.config FW_LOG_DENY_CRIT="yes" FW_LOG_DENY_ALL="no" FW_LOG_ACCEPT_CRIT="yes" FW_LOG_ACCEPT_ALL="no" to get detailed information on packets handled by your firewall rules.
Is their any logfile kept by this personal firewall of SuSE 7.3 and is their, where to look exactly ? Is their also a way to filter out these info.
/var/log/firewall contains the raw log info. To analyze there are several oss projects spread in the web. ask google for netfilter or iptables log analyzer and check for further information www.netfilter.org Yours Michael
participants (1)
-
GentooRulez