Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.networking > #663 > unrolled thread
| Started by | Christian Brandt <brandtc@psi5.com> |
|---|---|
| First post | 2011-10-02 11:17 +0200 |
| Last post | 2011-10-06 23:30 +0000 |
| Articles | 7 — 3 participants |
Back to article view | Back to comp.os.linux.networking
iptables limit all logging Christian Brandt <brandtc@psi5.com> - 2011-10-02 11:17 +0200
Re: iptables limit all logging "D. Stussy" <spam+newsgroups@bde-arc.ampr.org> - 2011-10-02 11:43 -0700
Re: iptables limit all logging Christian Brandt <brandtc@psi5.com> - 2011-10-03 08:32 +0200
Re: iptables limit all logging "D. Stussy" <spam+newsgroups@bde-arc.ampr.org> - 2011-10-03 15:02 -0700
Re: iptables limit all logging Christian Brandt <brandtc@psi5.com> - 2011-10-06 10:34 +0200
Re: iptables limit all logging "D. Stussy" <spam+newsgroups@bde-arc.ampr.org> - 2011-10-06 12:34 -0700
Re: iptables limit all logging Jorgen Grahn <grahn+nntp@snipabacken.se> - 2011-10-06 23:30 +0000
| From | Christian Brandt <brandtc@psi5.com> |
|---|---|
| Date | 2011-10-02 11:17 +0200 |
| Subject | iptables limit all logging |
| Message-ID | <j69a7i$nv7$1@news.m-online.net> |
I have several iptables -j LOG statements each with a 10/min limit and a describing --log-prefix. But I want one big limit while retaining the log-prefixes. In other words something like the non working example: iptables -A log_all -j LOG -m limit --limit 10/m iptables -A INPUT -j log_all --log-prefix="example1 " iptables -A OUTPUT -j log_all --log-prefix="example2 " Obviously "--log-prefix" is only valid for job LOG and not for generic chains. Possible at all? Any ideas?
[toc] | [next] | [standalone]
| From | "D. Stussy" <spam+newsgroups@bde-arc.ampr.org> |
|---|---|
| Date | 2011-10-02 11:43 -0700 |
| Message-ID | <j6abcu$4sb$1@snarked.org> |
| In reply to | #663 |
"Christian Brandt" <brandtc@psi5.com> wrote in message news:j69a7i$nv7$1@news.m-online.net... > I have several iptables -j LOG statements each with a 10/min limit and a > describing --log-prefix. But I want one big limit while retaining the > log-prefixes. > > In other words something like the non working example: > > iptables -A log_all -j LOG -m limit --limit 10/m > iptables -A INPUT -j log_all --log-prefix="example1 " > iptables -A OUTPUT -j log_all --log-prefix="example2 " > > Obviously "--log-prefix" is only valid for job LOG and not for generic > chains. > > Possible at all? Any ideas? Negate your condition: use "! --limit" and see if that works. I don't see that choice in the syntax on the manual page, but sometimes, not everything is documented. It does say, "(unless the '!' flag is used)" so perhaps it is indeed valid.
[toc] | [prev] | [next] | [standalone]
| From | Christian Brandt <brandtc@psi5.com> |
|---|---|
| Date | 2011-10-03 08:32 +0200 |
| Message-ID | <j6bkup$ht0$1@news.m-online.net> |
| In reply to | #665 |
Am 02.10.2011 20:43, schrieb D. Stussy:
> Negate your condition: use "! --limit" and see if that works. I don't
> see that choice in the syntax on the manual page, but sometimes, not
> everything is documented. It does say, "(unless the '!' flag is used)" so
> perhaps it is indeed valid.
That wouldn't make much sense (what is a negated limit?) and doesn't
work ("limit doesn support invert").
Also I simplified the example, I am not talking about two chains doing
logging but about a dozend, eg like:
iptables -A log_all -j LOG -m limit --limit 10/m
iptables -A chain1 -j log_all --log-prefix="chain1 "
iptables -A chain2 -j log_all --log-prefix="chain2 "
iptables -A chain3 -j log_all --log-prefix="chain3 "
iptables -A chain4 -j log_all --log-prefix="chain4 "
iptables -A chain5 -j log_all --log-prefix="chain5 "
iptables -A chain6 -j log_all --log-prefix="chain6 "
....
If I would simply abandon the log-prefix then things would work out
nice. But then I have a logfile full of very identical lines explaining
to me that undistinguishable things did happen :-)=
I need a way to feed some identificator towards the log_all chain.
Christian Brandt
[toc] | [prev] | [next] | [standalone]
| From | "D. Stussy" <spam+newsgroups@bde-arc.ampr.org> |
|---|---|
| Date | 2011-10-03 15:02 -0700 |
| Message-ID | <j6dbe1$akf$1@snarked.org> |
| In reply to | #668 |
"Christian Brandt" <brandtc@psi5.com> wrote in message
news:j6bkup$ht0$1@news.m-online.net...
> Am 02.10.2011 20:43, schrieb D. Stussy:
>
> > Negate your condition: use "! --limit" and see if that works. I
don't
> > see that choice in the syntax on the manual page, but sometimes, not
> > everything is documented. It does say, "(unless the '!' flag is used)"
so
> > perhaps it is indeed valid.
>
> That wouldn't make much sense (what is a negated limit?) and doesn't
> work ("limit doesn support invert").
It can make sense. Instead of calling the chain, use the inverted limit to
abort the chain.
As for "limit not supporting invert", the manual page says it does. So
either you're not using the most current version of iptables or we have a
valid bug to be reported.
> Also I simplified the example, I am not talking about two chains doing
> logging but about a dozend, eg like:
>
> iptables -A log_all -j LOG -m limit --limit 10/m
> iptables -A chain1 -j log_all --log-prefix="chain1 "
> iptables -A chain2 -j log_all --log-prefix="chain2 "
> iptables -A chain3 -j log_all --log-prefix="chain3 "
> iptables -A chain4 -j log_all --log-prefix="chain4 "
> iptables -A chain5 -j log_all --log-prefix="chain5 "
> iptables -A chain6 -j log_all --log-prefix="chain6 "
becomes:
iptables -A log_all -j RETURN -m limit ! --limit 10/m
iptables -A chain1 -j LOG --log-prefix="chain1 " ... (whatever other
conditions)
etc....
> ....
>
> If I would simply abandon the log-prefix then things would work out
> nice. But then I have a logfile full of very identical lines explaining
> to me that undistinguishable things did happen :-)=
>
> I need a way to feed some identificator towards the log_all chain.
[toc] | [prev] | [next] | [standalone]
| From | Christian Brandt <brandtc@psi5.com> |
|---|---|
| Date | 2011-10-06 10:34 +0200 |
| Message-ID | <j6jp60$5sp$1@news.m-online.net> |
| In reply to | #669 |
Am 04.10.2011 00:02, schrieb D. Stussy: > As for "limit not supporting invert", the manual page says it does. So > either you're not using the most current version of iptables or we have a > valid bug to be reported. Things get funny now: My Debian6 comes with iptables 1.4.8 which DOESN'T support negated limits. My Ubuntu 10.04 comes with iptables 1.4.4 which DOES support negated limits. My Ubuntu 11.04 comes with iptables 1.4.10 which DOESN'T support negated limits. The official 1.4.12.1 and CHANGES show is should be supported since 1.4.8 everywhere. Talk about version hell :-9 Christian Brandt
[toc] | [prev] | [next] | [standalone]
| From | "D. Stussy" <spam+newsgroups@bde-arc.ampr.org> |
|---|---|
| Date | 2011-10-06 12:34 -0700 |
| Message-ID | <j6kvsf$f7r$1@snarked.org> |
| In reply to | #670 |
"Christian Brandt" <brandtc@psi5.com> wrote in message news:j6jp60$5sp$1@news.m-online.net... > Am 04.10.2011 00:02, schrieb D. Stussy: > > As for "limit not supporting invert", the manual page says it does. So > > either you're not using the most current version of iptables or we have a > > valid bug to be reported. > > Things get funny now: > > My Debian6 comes with iptables 1.4.8 which DOESN'T support negated limits. > > My Ubuntu 10.04 comes with iptables 1.4.4 which DOES support negated > limits. > > My Ubuntu 11.04 comes with iptables 1.4.10 which DOESN'T support > negated limits. > > The official 1.4.12.1 and CHANGES show is should be supported since > 1.4.8 everywhere. > > Talk about version hell :-9 That's why I recompile critical programs from source and upgrade via source.
[toc] | [prev] | [next] | [standalone]
| From | Jorgen Grahn <grahn+nntp@snipabacken.se> |
|---|---|
| Date | 2011-10-06 23:30 +0000 |
| Message-ID | <slrnj8segj.1bk.grahn+nntp@frailea.sa.invalid> |
| In reply to | #670 |
On Thu, 2011-10-06, Christian Brandt wrote: > Am 04.10.2011 00:02, schrieb D. Stussy: >> As for "limit not supporting invert", the manual page says it does. So >> either you're not using the most current version of iptables or we have a >> valid bug to be reported. > > Things get funny now: > > My Debian6 comes with iptables 1.4.8 which DOESN'T support negated limits. > > My Ubuntu 10.04 comes with iptables 1.4.4 which DOES support negated > limits. > > My Ubuntu 11.04 comes with iptables 1.4.10 which DOESN'T support > negated limits. > > The official 1.4.12.1 and CHANGES show is should be supported since > 1.4.8 everywhere. Are you sure you're not looking at the 1.4.9 entry, aka "Changes /from/ 1.4.8"? The 1.4.8 entry in /usr/share/doc/iptables/changelog.gz (provided via Debian) doesn't say anything has happened to limits. 1.4.7 fixed the documentation; maybe doc bugs caused some of this confusion: "doc: fix limit manpage to reflect actual supported syntax" /Jorgen -- // Jorgen Grahn <grahn@ Oo o. . . \X/ snipabacken.se> O o .
[toc] | [prev] | [standalone]
Back to top | Article view | comp.os.linux.networking
csiph-web