Path: csiph.com!x330-a1.tempe.blueboxinc.net!usenet.pasdenom.info!aioe.org!news.glorb.com!news-in-01.newsfeed.easynews.com!easynews!core-easynews-01!easynews.com!en-nntp-14.dc1.easynews.com.POSTED!not-for-mail From: Harry Putnam Newsgroups: comp.os.linux.networking Subject: DMZ for logging Organization: Still searching... User-Agent: Gnus/5.110018 (No Gnus v0.18) Emacs/24.0.92 (gnu/linux) Message-ID: <87mx95st8m.fsf@newsguy.com> Cancel-Lock: sha1:DS56rqb+yDt3x62SdLAHLM8CVYI= MIME-Version: 1.0 Content-Type: text/plain Lines: 14 X-Complaints-To: abuse@easynews.com X-Complaints-Info: Please be sure to forward a copy of ALL headers otherwise we will be unable to process your complaint properly. Date: Sun, 29 Jan 2012 23:35:05 -0500 Xref: x330-a1.tempe.blueboxinc.net comp.os.linux.networking:1022 I hope to find experienced iptables users here who can tell me if this idea is something I could setup with iptables. I'd like to get a real good idea of what is coming at me from the internet. Is there a technique where all incoming connections are copied to a separate server that uses iptables to sort categorize and log incoming traffic, but then drops it. At least the portion that is at all suspect in any way. After a while I would start to know what is just taking up log space for no good reason and what is actually something likely to be malicious in intent. I want a first hand look at what comes down the pipe.