CentOS 6 下单独记录 iptables 日志

1. First,add a new chain with a reasonable name:

iptables -N LOGGING


2. Next,insert a rule at the appropriate point (hence me using --line-numbers above). You could replace the existing REJECT at line 5 in its entirety as its functionality will be moved into the LOGGING chain (where I change it to a DROP anyway):

@L_301_0@

iptables -I INPUT 5 -j LOGGING


3. Add the actual logging rule next

iptables -A LOGGING -j LOG --log-prefix "DROP: " --log-level 7

iptables -A LOGGING -j DROP

service iptables save

service iptables restart

wKiom1d4iNGzFVhIAAH_v_nkipc207.jpg


4. vi /etc/rsyslog.conf

kern.debug/var/log/iptables.log


service rsyslog restart


5. vi /etc/logrotate.d/syslog

add /var/log/iptables.log to list of filenames

相关文章

有时候CentOS工作在无互联网的环境下,需要在离线环境下安装一些组件,这次实现的是模拟在离线环境下安...
首先参照https://www.cnblogs.com/wdw984/p/13330074.html,来进行如何安装Centos和离线下载rpm包。 离...
有两个.NET CORE3.1网站部署在CentOS7上(内网IP是192.168.2.32),现在想实现访问http://192.168.2.32...
1、yum -y install vsftpd 安装vsftpd 2、配置vsftpd的配置文件(/etc/vsftpd/vsftpd.conf)主要修改以...
首先去mysql官网下载mysql的离线rpm安装包(https://downloads.mysql.com/archives/community/) Mysql...
第一步下载erlang环境并安装: wget https://packages.erlang-solutions.com/erlang/rpm/centos/7/x86_...