Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #1027

Re: DMZ for logging

Path csiph.com!x330-a1.tempe.blueboxinc.net!aioe.org!news.glorb.com!npeer02.iad.highwinds-media.com!news.highwinds-media.com!feed-me.highwinds-media.com!spln!extra.newsguy.com!newsp.newsguy.com!news7
From Harry Putnam <reader@newsguy.com>
Newsgroups comp.os.linux.networking
Subject Re: DMZ for logging
Date Mon, 30 Jan 2012 10:34:29 -0500
Organization Still searching...
Lines 63
Message-ID <877h09rypm.fsf@newsguy.com> (permalink)
References <87mx95st8m.fsf@newsguy.com> <4f267865$0$1378$4fafbaef@reader2.news.tin.it>
NNTP-Posting-Host p7f730ce1d15ab4cc4a576fdb1c5092bf9d7c72b920ea5bb2.newsdawg.com
Mime-Version 1.0
Content-Type text/plain
User-Agent Gnus/5.110018 (No Gnus v0.18) Emacs/24.0.92 (gnu/linux)
Cancel-Lock sha1:0++6DQ+DJxJi1P8k8J+aWuiUuIo=
Xref x330-a1.tempe.blueboxinc.net comp.os.linux.networking:1027

Show key headers only | View raw


Enrico <enrico204@virgilio.it> writes:

> Il 30/01/2012 05:35, Harry Putnam ha scritto:
>> Is there a technique where all incoming connections are
>> copied to a separate server that uses iptables to sort categorize and
>> log incoming traffic, but then drops it.
>
> If you have the WAN on ethernet (from the router, for example) and
> your traffic flow isn't big, you can setup a mirror port on a switch,
> if you have one, then drop all traffic at the end of chains (policy
> action) into the logging server (after LOG rules).

I'm not following there about the mirror on a switch.  Can you explain
a bit more?

> You need to assign all public IP to the "logging server" and make sure
> that there are no connection attempts from that server out that
> interface. Maybe you can only use "promisc" with "ifconfig", but I'm
> not sure.

I don't follow that either.  Why do all public IP need to be assigned
to logging server... and if so how will any legitimate traffic get
thru to private lan?

My setup is pretty basic (except for the 2nd router I am fiddling
with being stuck awkwardly in there) and looks like this (roughly).  
                             
                 internet
                    |
               Satellite modem
                    |
           ===  cisco WRT120 & firewall==
           |    |      |       |        |
           |    |      |       |        | 
         mob1  mob2  desktop  mob3    router2 (WR1043ND)
       2 nics                           |                     
          |                            subnet
          |                             | 
          |_____________________________|


The middle level there is on 192.168.1.0/24
                subnet is on 192.168.2.0/24

One of the laptops (far left) has its wifi talking to net ..1.0/24 and
its ethernet port talking to net ..2.0/24

So the second router (far right) has its wan port connected to the
(cisco) lan router's lan port (router2 wan to router1 lan).  2nd
router's own lan ports are supplying the subnet 192.168.2.0

This is not supposed to be my attempt at the setup I'm asking about.
It's just me working on the 2nd router... adding openwrt router
software and familiarizing myself with iptables before I land myself
in hot water. 

I think the setup I'm after would look about the same but would allow
only 1 lan port out, and a well filtered one.  That would be to get at
the logs being compiled there.

Iptables would be running on 2nd router.

 

Back to comp.os.linux.networking | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

DMZ for logging Harry Putnam <reader@newsguy.com> - 2012-01-29 23:35 -0500
  Re: DMZ for logging Enrico <enrico204@virgilio.it> - 2012-01-30 12:00 +0100
    Re: DMZ for logging Harry Putnam <reader@newsguy.com> - 2012-01-30 10:34 -0500
  Re: DMZ for logging J G Miller <miller@yoyo.ORG> - 2012-01-30 14:14 +0000
    Re: DMZ for logging Harry Putnam <reader@newsguy.com> - 2012-01-30 09:40 -0500
      Re: DMZ for logging J G Miller <miller@yoyo.ORG> - 2012-01-30 15:51 +0000
        Re: DMZ for logging Jorgen Grahn <grahn+nntp@snipabacken.se> - 2012-01-30 16:06 +0000
  Re: DMZ for logging Dale Dellutri <ddelQQQlutr@panQQQix.com> - 2012-01-30 15:35 +0000
    Re: DMZ for logging Jorgen Grahn <grahn+nntp@snipabacken.se> - 2012-01-30 16:01 +0000
    Re: DMZ for logging Harry Putnam <reader@newsguy.com> - 2012-01-31 10:28 -0500
      Re: DMZ for logging Enrico <enrico204@virgilio.it> - 2012-01-31 20:26 +0100

csiph-web