Re: Firewall logs and analyzing tools

2003-06-20 Thread Alvin Oga
; grep icmp /var/log/messages grep ftp /var/log/messages grep telnet /var/log/messages egrep -iv "ssh|icmp|ftp|telnet" /var/log/messages grep error /var/log/http/error_log plot all that out in whatever presentation you want firewall logs

Re: Firewall logs and analyzing tools

2003-06-20 Thread bob parker
On Fri, 20 Jun 2003 02:45, Massimo Villa wrote: > Is there anybody who knows a analyzing, monitoring and > reporting tools of iptables logs to discover possible attacks > and statistics informations? > logcheck might help, it distills the logs and emails the result to you or other designated recip

Firewall logs and analyzing tools

2003-06-19 Thread Massimo Villa
Is there anybody who knows a analyzing, monitoring and reporting tools of iptables logs to discover possible attacks and statistics informations? thanks Massimo -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: What's murhpy.debian.org doing in my firewall logs ?

2002-06-03 Thread D.J. Bolderman
I think i'm all done. I've setup relayclients, and opened the smtp port to the internet. The firewall msg's are gone so that's a good point. However, http://www.abuse.net/relay.html gives me a fault at step 6 mentioning that there 'might' be a relay problem. I tried another relay test-site and all

Re: What's murhpy.debian.org doing in my firewall logs ?

2002-06-03 Thread Henrique de Moraes Holschuh
On Mon, 03 Jun 2002, D.J. Bolderman wrote: > Ok, thanks i will look into this. If I just allow murphy.debian.org access > to my system, the problem would also go away wouldn't it ? > I also guess it's better to use a dns server on my server so I can control > these things beter ? You have to eithe

Re: What's murhpy.debian.org doing in my firewall logs ?

2002-06-03 Thread Colin Watson
On Mon, Jun 03, 2002 at 10:52:55AM -, D.J. Bolderman wrote: > Ok, thanks i will look into this. If I just allow murphy.debian.org access > to my system, the problem would also go away wouldn't it ? No, other systems will try to deliver mail to you in the same way. > I also guess it's better t

Re: What's murhpy.debian.org doing in my firewall logs ?

2002-06-03 Thread Mark Janssen
On Mon, 2002-06-03 at 14:19, D.J. Bolderman wrote: > I've just opened my firewall for murphy. Mark, how's your setup related to > this ? Do you also use bsmtp ? Ja... maar ik draai mijn eigen mailserver (die van xs4all zijn vaak erg traag). Dus mijn firewall staat nogmaal ook open voor smtp. Mark

Re: What's murhpy.debian.org doing in my firewall logs ?

2002-06-03 Thread Mark Janssen
P.s. zet je reply-to goed. Deze staat namelijk op [EMAIL PROTECTED] en dat is geen geldig adres... dus moet ik iedere keer .xs4all.nl er achter typen... Mark -- Mark Janssen -- maniac(at)maniac.nl -- GnuPG Key Id: 357D2178 Unix / Linux, Open-Source and Internet Consultant @ SyConOS IT Maniac.nl

Re: What's murhpy.debian.org doing in my firewall logs ?

2002-06-03 Thread D.J. Bolderman
I've just opened my firewall for murphy. Mark, how's your setup related to this ? Do you also use bsmtp ? > On Mon, 2002-06-03 at 12:40, D.J. Bolderman wrote: >> Could you please give me a hint where to fix this (i'm just a clueless >> niewbie) >> Thanks. >> >> > On Mon, 03 Jun 2002, D.J. Bolderman

Re: What's murhpy.debian.org doing in my firewall logs ?

2002-06-03 Thread Mark Janssen
On Mon, 2002-06-03 at 12:40, D.J. Bolderman wrote: > Could you please give me a hint where to fix this (i'm just a clueless > niewbie) > Thanks. > > > On Mon, 03 Jun 2002, D.J. Bolderman wrote: > >> What's the problem here ? Why doesn't murphy.debian.org deliver mail > >> to my provider's mail ser

Re: What's murhpy.debian.org doing in my firewall logs ?

2002-06-03 Thread D.J. Bolderman
Ok, thanks i will look into this. If I just allow murphy.debian.org access to my system, the problem would also go away wouldn't it ? I also guess it's better to use a dns server on my server so I can control these things beter ? Thanks Dick > On Mon, 03 Jun 2002, D.J. Bolderman wrote: >> Could y

Re: What's murhpy.debian.org doing in my firewall logs ?

2002-06-03 Thread martin f krafft
also sprach D.J. Bolderman <[EMAIL PROTECTED]> [2002.06.03.1240 +0200]: > Could you please give me a hint where to fix this (i'm just a clueless > niewbie) where is your DNS server? do you control it yourself, or is it with a provider? -- martin; (greetings from the heart of the sun

Re: What's murhpy.debian.org doing in my firewall logs ?

2002-06-03 Thread Henrique de Moraes Holschuh
On Mon, 03 Jun 2002, D.J. Bolderman wrote: > Could you please give me a hint where to fix this (i'm just a clueless > niewbie) The change must be made in the nameserver that answers for bolderman.xs4all.nl. It is probably operated by your provider (there are no nameservers listed for bolderman.xs4

Re: What's murhpy.debian.org doing in my firewall logs ?

2002-06-03 Thread D.J. Bolderman
Could you please give me a hint where to fix this (i'm just a clueless niewbie) Thanks. > On Mon, 03 Jun 2002, D.J. Bolderman wrote: >> What's the problem here ? Why doesn't murphy.debian.org deliver mail >> to my provider's mail server ? > > mx bolderman.xs4all.nl > bolderman.xs4all.nl MX

Re: What's murhpy.debian.org doing in my firewall logs ?

2002-06-03 Thread Henrique de Moraes Holschuh
On Mon, 03 Jun 2002, D.J. Bolderman wrote: > What's the problem here ? Why doesn't murphy.debian.org deliver mail to my > provider's mail server ? mx bolderman.xs4all.nl bolderman.xs4all.nl MX 100 mx2.xs4all.nl bolderman.xs4all.nl MX 100 mx3.xs4all.nl bolderman.xs4all.nl MX

What's murhpy.debian.org doing in my firewall logs ?

2002-06-03 Thread D.J. Bolderman
Hi All, In my iptables configuration, I block all incoming smtp traffic to my system except from the mailservers from my internet provider. However, sinces i'm subscribed to this list, i see a lot of dropped packets in my logs from murphy.debian.org. What's the problem here ? Why doesn't murphy.de

Re: Firewall Logs

2002-03-30 Thread Osamu Aoki
> I'm running a simple router/firewall with a Herc graphics card, so I > can't have anything graphic =] Install "mc" by "apt-get update; apt-get install mc". Then from root account: # cd /var/log # mc Then you can see all the log files by cursor keys and ent

Firewall Logs

2002-03-29 Thread Alan Poulton
Hi List I'm running Debian Potato, upgraded to Kernel 2.4.17 via Bunk.. Where are the logs for IPTables kept, and how readable are they? If they're tough to read, is there a (non-GUI) utility to make it easier? I'm running a simple router/firewall with a Herc graphics card, so I can't have anythi