13.07.2015 Views

IPTables: Catene - democritos

IPTables: Catene - democritos

IPTables: Catene - democritos

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Logging: comandiUtilizzando le catene qui riportate, basta rimpiazzare opportunamente nelleregole precedenti i vari “-j DROP/REJECT” con “-j logndrop/lognreject”.INPUT:-A logndrop -m unclean -j LOG --log-level debug \--log-prefix "iptables: unclean packet: " \--log-tcp-sequence --log-tcp-options --log-ip-options-A logndrop -m limit --limit 5/m --limit-burst 60 -j LOG \--log-level debug --log-prefix "iptables: "-A logndrop -j UDROP-A UDROP -m limit --limit 5/m --limit-burst 30 -j ULOG-A UDROP -j DROPOUTPUT:-A lognreject -m unclean -j LOG --log-level debug \--log-prefix "iptables: unclean: " --log-tcp-sequence \--log-tcp-options --log-ip-options --log-uid-A lognreject -m limit --limit 5/m --limit-burst 60 -j LOG \--log-level debug --log-prefix "iptables: outdrop: " \--log-uid-A lognreject -j REJECT --reject-with icmp-admin-prohibited41

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!