Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #663 > unrolled thread

iptables limit all logging

Started byChristian Brandt <brandtc@psi5.com>
First post2011-10-02 11:17 +0200
Last post2011-10-06 23:30 +0000
Articles 7 — 3 participants

Back to article view | Back to comp.os.linux.networking


Contents

  iptables limit all logging Christian Brandt <brandtc@psi5.com> - 2011-10-02 11:17 +0200
    Re: iptables limit all logging "D. Stussy" <spam+newsgroups@bde-arc.ampr.org> - 2011-10-02 11:43 -0700
      Re: iptables limit all logging Christian Brandt <brandtc@psi5.com> - 2011-10-03 08:32 +0200
        Re: iptables limit all logging "D. Stussy" <spam+newsgroups@bde-arc.ampr.org> - 2011-10-03 15:02 -0700
          Re: iptables limit all logging Christian Brandt <brandtc@psi5.com> - 2011-10-06 10:34 +0200
            Re: iptables limit all logging "D. Stussy" <spam+newsgroups@bde-arc.ampr.org> - 2011-10-06 12:34 -0700
            Re: iptables limit all logging Jorgen Grahn <grahn+nntp@snipabacken.se> - 2011-10-06 23:30 +0000

#663 — iptables limit all logging

FromChristian Brandt <brandtc@psi5.com>
Date2011-10-02 11:17 +0200
Subjectiptables limit all logging
Message-ID<j69a7i$nv7$1@news.m-online.net>
I have several iptables -j LOG statements each with a 10/min limit and a
describing --log-prefix. But I want one big limit while retaining the
log-prefixes.

In other words something like the non working example:

iptables -A log_all -j LOG -m limit --limit 10/m
iptables -A INPUT  -j log_all --log-prefix="example1 "
iptables -A OUTPUT -j log_all --log-prefix="example2 "

Obviously "--log-prefix" is only valid for job LOG and not for generic
chains.

Possible at all? Any ideas?

[toc] | [next] | [standalone]


#665

From"D. Stussy" <spam+newsgroups@bde-arc.ampr.org>
Date2011-10-02 11:43 -0700
Message-ID<j6abcu$4sb$1@snarked.org>
In reply to#663
"Christian Brandt" <brandtc@psi5.com> wrote in message
news:j69a7i$nv7$1@news.m-online.net...
> I have several iptables -j LOG statements each with a 10/min limit and a
> describing --log-prefix. But I want one big limit while retaining the
> log-prefixes.
>
> In other words something like the non working example:
>
> iptables -A log_all -j LOG -m limit --limit 10/m
> iptables -A INPUT  -j log_all --log-prefix="example1 "
> iptables -A OUTPUT -j log_all --log-prefix="example2 "
>
> Obviously "--log-prefix" is only valid for job LOG and not for generic
> chains.
>
> Possible at all? Any ideas?

Negate your condition:  use  "! --limit" and see if that works.  I don't
see that choice in the syntax on the manual page, but sometimes, not
everything is documented.  It does say, "(unless the '!' flag is used)" so
perhaps it is indeed valid.

[toc] | [prev] | [next] | [standalone]


#668

FromChristian Brandt <brandtc@psi5.com>
Date2011-10-03 08:32 +0200
Message-ID<j6bkup$ht0$1@news.m-online.net>
In reply to#665
Am 02.10.2011 20:43, schrieb D. Stussy:

> Negate your condition:  use  "! --limit" and see if that works.  I don't
> see that choice in the syntax on the manual page, but sometimes, not
> everything is documented.  It does say, "(unless the '!' flag is used)" so
> perhaps it is indeed valid.

 That wouldn't make much sense (what is a negated limit?) and doesn't
work ("limit doesn support invert").

 Also I simplified the example, I am not talking about two chains doing
logging but about a dozend, eg like:

iptables -A log_all -j LOG -m limit --limit 10/m
iptables -A chain1 -j log_all --log-prefix="chain1 "
iptables -A chain2 -j log_all --log-prefix="chain2 "
iptables -A chain3 -j log_all --log-prefix="chain3 "
iptables -A chain4 -j log_all --log-prefix="chain4 "
iptables -A chain5 -j log_all --log-prefix="chain5 "
iptables -A chain6 -j log_all --log-prefix="chain6 "
 ....

 If I would simply abandon the log-prefix then things would work out
nice. But then I have a logfile full of very identical lines explaining
to me that undistinguishable things did happen :-)=

 I need a way to feed some identificator towards the log_all chain.

 Christian Brandt

[toc] | [prev] | [next] | [standalone]


#669

From"D. Stussy" <spam+newsgroups@bde-arc.ampr.org>
Date2011-10-03 15:02 -0700
Message-ID<j6dbe1$akf$1@snarked.org>
In reply to#668
"Christian Brandt" <brandtc@psi5.com> wrote in message
news:j6bkup$ht0$1@news.m-online.net...
> Am 02.10.2011 20:43, schrieb D. Stussy:
>
> > Negate your condition:  use  "! --limit" and see if that works.  I
don't
> > see that choice in the syntax on the manual page, but sometimes, not
> > everything is documented.  It does say, "(unless the '!' flag is used)"
so
> > perhaps it is indeed valid.
>
>  That wouldn't make much sense (what is a negated limit?) and doesn't
> work ("limit doesn support invert").

It can make sense.  Instead of calling the chain, use the inverted limit to
abort the chain.

As for "limit not supporting invert", the manual page says it does.  So
either you're not using the most current version of iptables or we have a
valid bug to be reported.

>  Also I simplified the example, I am not talking about two chains doing
> logging but about a dozend, eg like:
>
> iptables -A log_all -j LOG -m limit --limit 10/m
> iptables -A chain1 -j log_all --log-prefix="chain1 "
> iptables -A chain2 -j log_all --log-prefix="chain2 "
> iptables -A chain3 -j log_all --log-prefix="chain3 "
> iptables -A chain4 -j log_all --log-prefix="chain4 "
> iptables -A chain5 -j log_all --log-prefix="chain5 "
> iptables -A chain6 -j log_all --log-prefix="chain6 "

becomes:

iptables -A log_all -j RETURN -m limit ! --limit 10/m
iptables -A chain1 -j LOG --log-prefix="chain1 "  ... (whatever other
conditions)
etc....

>  ....
>
>  If I would simply abandon the log-prefix then things would work out
> nice. But then I have a logfile full of very identical lines explaining
> to me that undistinguishable things did happen :-)=
>
>  I need a way to feed some identificator towards the log_all chain.

[toc] | [prev] | [next] | [standalone]


#670

FromChristian Brandt <brandtc@psi5.com>
Date2011-10-06 10:34 +0200
Message-ID<j6jp60$5sp$1@news.m-online.net>
In reply to#669
Am 04.10.2011 00:02, schrieb D. Stussy:
> As for "limit not supporting invert", the manual page says it does.  So
> either you're not using the most current version of iptables or we have a
> valid bug to be reported.

Things get funny now:

 My Debian6 comes with iptables 1.4.8 which DOESN'T support negated limits.

 My Ubuntu 10.04 comes with iptables 1.4.4 which DOES support negated
limits.

 My Ubuntu 11.04 comes with iptables 1.4.10 which DOESN'T support
negated limits.

 The official 1.4.12.1 and CHANGES show is should be supported since
1.4.8 everywhere.

 Talk about version hell :-9

 Christian Brandt

[toc] | [prev] | [next] | [standalone]


#671

From"D. Stussy" <spam+newsgroups@bde-arc.ampr.org>
Date2011-10-06 12:34 -0700
Message-ID<j6kvsf$f7r$1@snarked.org>
In reply to#670
"Christian Brandt" <brandtc@psi5.com> wrote in message
news:j6jp60$5sp$1@news.m-online.net...
> Am 04.10.2011 00:02, schrieb D. Stussy:
> > As for "limit not supporting invert", the manual page says it does.  So
> > either you're not using the most current version of iptables or we have
a
> > valid bug to be reported.
>
> Things get funny now:
>
>  My Debian6 comes with iptables 1.4.8 which DOESN'T support negated
limits.
>
>  My Ubuntu 10.04 comes with iptables 1.4.4 which DOES support negated
> limits.
>
>  My Ubuntu 11.04 comes with iptables 1.4.10 which DOESN'T support
> negated limits.
>
>  The official 1.4.12.1 and CHANGES show is should be supported since
> 1.4.8 everywhere.
>
>  Talk about version hell :-9

That's why I recompile critical programs from source and upgrade via
source.

[toc] | [prev] | [next] | [standalone]


#672

FromJorgen Grahn <grahn+nntp@snipabacken.se>
Date2011-10-06 23:30 +0000
Message-ID<slrnj8segj.1bk.grahn+nntp@frailea.sa.invalid>
In reply to#670
On Thu, 2011-10-06, Christian Brandt wrote:
> Am 04.10.2011 00:02, schrieb D. Stussy:
>> As for "limit not supporting invert", the manual page says it does.  So
>> either you're not using the most current version of iptables or we have a
>> valid bug to be reported.
>
> Things get funny now:
>
>  My Debian6 comes with iptables 1.4.8 which DOESN'T support negated limits.
>
>  My Ubuntu 10.04 comes with iptables 1.4.4 which DOES support negated
> limits.
>
>  My Ubuntu 11.04 comes with iptables 1.4.10 which DOESN'T support
> negated limits.
>
>  The official 1.4.12.1 and CHANGES show is should be supported since
> 1.4.8 everywhere.

Are you sure you're not looking at the 1.4.9 entry, aka "Changes
/from/ 1.4.8"?  The 1.4.8 entry in /usr/share/doc/iptables/changelog.gz
(provided via Debian) doesn't say anything has happened to limits.

1.4.7 fixed the documentation; maybe doc bugs caused some of this
confusion:

  "doc: fix limit manpage to reflect actual supported syntax"

/Jorgen

-- 
  // Jorgen Grahn <grahn@  Oo  o.   .     .
\X/     snipabacken.se>   O  o   .

[toc] | [prev] | [standalone]


Back to top | Article view | comp.os.linux.networking


csiph-web