Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #669

Re: iptables limit all logging

From "D. Stussy" <spam+newsgroups@bde-arc.ampr.org>
Newsgroups comp.os.linux.networking
Subject Re: iptables limit all logging
Date 2011-10-03 15:02 -0700
Message-ID <j6dbe1$akf$1@snarked.org> (permalink)
References <j69a7i$nv7$1@news.m-online.net> <j6abcu$4sb$1@snarked.org> <j6bkup$ht0$1@news.m-online.net>

Show all headers | View raw


"Christian Brandt" <brandtc@psi5.com> wrote in message
news:j6bkup$ht0$1@news.m-online.net...
> Am 02.10.2011 20:43, schrieb D. Stussy:
>
> > Negate your condition:  use  "! --limit" and see if that works.  I
don't
> > see that choice in the syntax on the manual page, but sometimes, not
> > everything is documented.  It does say, "(unless the '!' flag is used)"
so
> > perhaps it is indeed valid.
>
>  That wouldn't make much sense (what is a negated limit?) and doesn't
> work ("limit doesn support invert").

It can make sense.  Instead of calling the chain, use the inverted limit to
abort the chain.

As for "limit not supporting invert", the manual page says it does.  So
either you're not using the most current version of iptables or we have a
valid bug to be reported.

>  Also I simplified the example, I am not talking about two chains doing
> logging but about a dozend, eg like:
>
> iptables -A log_all -j LOG -m limit --limit 10/m
> iptables -A chain1 -j log_all --log-prefix="chain1 "
> iptables -A chain2 -j log_all --log-prefix="chain2 "
> iptables -A chain3 -j log_all --log-prefix="chain3 "
> iptables -A chain4 -j log_all --log-prefix="chain4 "
> iptables -A chain5 -j log_all --log-prefix="chain5 "
> iptables -A chain6 -j log_all --log-prefix="chain6 "

becomes:

iptables -A log_all -j RETURN -m limit ! --limit 10/m
iptables -A chain1 -j LOG --log-prefix="chain1 "  ... (whatever other
conditions)
etc....

>  ....
>
>  If I would simply abandon the log-prefix then things would work out
> nice. But then I have a logfile full of very identical lines explaining
> to me that undistinguishable things did happen :-)=
>
>  I need a way to feed some identificator towards the log_all chain.

Back to comp.os.linux.networking | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

iptables limit all logging Christian Brandt <brandtc@psi5.com> - 2011-10-02 11:17 +0200
  Re: iptables limit all logging "D. Stussy" <spam+newsgroups@bde-arc.ampr.org> - 2011-10-02 11:43 -0700
    Re: iptables limit all logging Christian Brandt <brandtc@psi5.com> - 2011-10-03 08:32 +0200
      Re: iptables limit all logging "D. Stussy" <spam+newsgroups@bde-arc.ampr.org> - 2011-10-03 15:02 -0700
        Re: iptables limit all logging Christian Brandt <brandtc@psi5.com> - 2011-10-06 10:34 +0200
          Re: iptables limit all logging "D. Stussy" <spam+newsgroups@bde-arc.ampr.org> - 2011-10-06 12:34 -0700
          Re: iptables limit all logging Jorgen Grahn <grahn+nntp@snipabacken.se> - 2011-10-06 23:30 +0000

csiph-web