Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #1022

DMZ for logging

From Harry Putnam <reader@newsguy.com>
Newsgroups comp.os.linux.networking
Subject DMZ for logging
Organization Still searching...
Message-ID <87mx95st8m.fsf@newsguy.com> (permalink)
Date 2012-01-29 23:35 -0500

Show all headers | View raw


I hope to find experienced iptables users here who can tell me if this
idea is something I could setup with iptables.

I'd like to get a real good idea of what is coming at me from the
internet. Is there a technique where all incoming connections are
copied to a separate server that uses iptables to sort categorize and
log incoming traffic, but then drops it.  At least the portion that is
at all suspect in any way.

After a while I would start to know what is just taking up log space
for no good reason and what is actually something likely to be
malicious in intent.

I want a first hand look at what comes down the pipe.

Back to comp.os.linux.networking | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

DMZ for logging Harry Putnam <reader@newsguy.com> - 2012-01-29 23:35 -0500
  Re: DMZ for logging Enrico <enrico204@virgilio.it> - 2012-01-30 12:00 +0100
    Re: DMZ for logging Harry Putnam <reader@newsguy.com> - 2012-01-30 10:34 -0500
  Re: DMZ for logging J G Miller <miller@yoyo.ORG> - 2012-01-30 14:14 +0000
    Re: DMZ for logging Harry Putnam <reader@newsguy.com> - 2012-01-30 09:40 -0500
      Re: DMZ for logging J G Miller <miller@yoyo.ORG> - 2012-01-30 15:51 +0000
        Re: DMZ for logging Jorgen Grahn <grahn+nntp@snipabacken.se> - 2012-01-30 16:06 +0000
  Re: DMZ for logging Dale Dellutri <ddelQQQlutr@panQQQix.com> - 2012-01-30 15:35 +0000
    Re: DMZ for logging Jorgen Grahn <grahn+nntp@snipabacken.se> - 2012-01-30 16:01 +0000
    Re: DMZ for logging Harry Putnam <reader@newsguy.com> - 2012-01-31 10:28 -0500
      Re: DMZ for logging Enrico <enrico204@virgilio.it> - 2012-01-31 20:26 +0100

csiph-web