Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #1022

DMZ for logging

Path csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!aioe.org!news.glorb.com!news-in-01.newsfeed.easynews.com!easynews!core-easynews-01!easynews.com!en-nntp-14.dc1.easynews.com.POSTED!not-for-mail
From Harry Putnam <reader@newsguy.com>
Newsgroups comp.os.linux.networking
Subject DMZ for logging
Organization Still searching...
User-Agent Gnus/5.110018 (No Gnus v0.18) Emacs/24.0.92 (gnu/linux)
Message-ID <87mx95st8m.fsf@newsguy.com> (permalink)
Cancel-Lock sha1:DS56rqb+yDt3x62SdLAHLM8CVYI=
MIME-Version 1.0
Content-Type text/plain
Lines 14
X-Complaints-To abuse@easynews.com
X-Complaints-Info Please be sure to forward a copy of ALL headers otherwise we will be unable to process your complaint properly.
Date Sun, 29 Jan 2012 23:35:05 -0500
Xref x330-a1.tempe.blueboxinc.net comp.os.linux.networking:1022

Show key headers only | View raw


I hope to find experienced iptables users here who can tell me if this
idea is something I could setup with iptables.

I'd like to get a real good idea of what is coming at me from the
internet. Is there a technique where all incoming connections are
copied to a separate server that uses iptables to sort categorize and
log incoming traffic, but then drops it.  At least the portion that is
at all suspect in any way.

After a while I would start to know what is just taking up log space
for no good reason and what is actually something likely to be
malicious in intent.

I want a first hand look at what comes down the pipe.

Back to comp.os.linux.networking | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

DMZ for logging Harry Putnam <reader@newsguy.com> - 2012-01-29 23:35 -0500
  Re: DMZ for logging Enrico <enrico204@virgilio.it> - 2012-01-30 12:00 +0100
    Re: DMZ for logging Harry Putnam <reader@newsguy.com> - 2012-01-30 10:34 -0500
  Re: DMZ for logging J G Miller <miller@yoyo.ORG> - 2012-01-30 14:14 +0000
    Re: DMZ for logging Harry Putnam <reader@newsguy.com> - 2012-01-30 09:40 -0500
      Re: DMZ for logging J G Miller <miller@yoyo.ORG> - 2012-01-30 15:51 +0000
        Re: DMZ for logging Jorgen Grahn <grahn+nntp@snipabacken.se> - 2012-01-30 16:06 +0000
  Re: DMZ for logging Dale Dellutri <ddelQQQlutr@panQQQix.com> - 2012-01-30 15:35 +0000
    Re: DMZ for logging Jorgen Grahn <grahn+nntp@snipabacken.se> - 2012-01-30 16:01 +0000
    Re: DMZ for logging Harry Putnam <reader@newsguy.com> - 2012-01-31 10:28 -0500
      Re: DMZ for logging Enrico <enrico204@virgilio.it> - 2012-01-31 20:26 +0100

csiph-web