Path: csiph.com!x330-a1.tempe.blueboxinc.net!aioe.org!news.glorb.com!npeer02.iad.highwinds-media.com!news.highwinds-media.com!feed-me.highwinds-media.com!spln!extra.newsguy.com!newsp.newsguy.com!news7 From: Harry Putnam Newsgroups: comp.os.linux.networking Subject: Re: DMZ for logging Date: Mon, 30 Jan 2012 10:34:29 -0500 Organization: Still searching... Lines: 63 Message-ID: <877h09rypm.fsf@newsguy.com> References: <87mx95st8m.fsf@newsguy.com> <4f267865$0$1378$4fafbaef@reader2.news.tin.it> NNTP-Posting-Host: p7f730ce1d15ab4cc4a576fdb1c5092bf9d7c72b920ea5bb2.newsdawg.com Mime-Version: 1.0 Content-Type: text/plain User-Agent: Gnus/5.110018 (No Gnus v0.18) Emacs/24.0.92 (gnu/linux) Cancel-Lock: sha1:0++6DQ+DJxJi1P8k8J+aWuiUuIo= Xref: x330-a1.tempe.blueboxinc.net comp.os.linux.networking:1027 Enrico writes: > Il 30/01/2012 05:35, Harry Putnam ha scritto: >> Is there a technique where all incoming connections are >> copied to a separate server that uses iptables to sort categorize and >> log incoming traffic, but then drops it. > > If you have the WAN on ethernet (from the router, for example) and > your traffic flow isn't big, you can setup a mirror port on a switch, > if you have one, then drop all traffic at the end of chains (policy > action) into the logging server (after LOG rules). I'm not following there about the mirror on a switch. Can you explain a bit more? > You need to assign all public IP to the "logging server" and make sure > that there are no connection attempts from that server out that > interface. Maybe you can only use "promisc" with "ifconfig", but I'm > not sure. I don't follow that either. Why do all public IP need to be assigned to logging server... and if so how will any legitimate traffic get thru to private lan? My setup is pretty basic (except for the 2nd router I am fiddling with being stuck awkwardly in there) and looks like this (roughly). internet | Satellite modem | === cisco WRT120 & firewall== | | | | | | | | | | mob1 mob2 desktop mob3 router2 (WR1043ND) 2 nics | | subnet | | |_____________________________| The middle level there is on 192.168.1.0/24 subnet is on 192.168.2.0/24 One of the laptops (far left) has its wifi talking to net ..1.0/24 and its ethernet port talking to net ..2.0/24 So the second router (far right) has its wan port connected to the (cisco) lan router's lan port (router2 wan to router1 lan). 2nd router's own lan ports are supplying the subnet 192.168.2.0 This is not supposed to be my attempt at the setup I'm asking about. It's just me working on the 2nd router... adding openwrt router software and familiarizing myself with iptables before I land myself in hot water. I think the setup I'm after would look about the same but would allow only 1 lan port out, and a well filtered one. That would be to get at the logs being compiled there. Iptables would be running on 2nd router.