|
From: Friedrich L. <fl...@fl...> - 2003-05-30 21:25:42
|
Bruce Smith wrote: > I just uploaded my latest firewall script at: > > http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/devil-linux/build/config/etc/init.d/firewall.rules.2nic?rev=HEAD > Add a comment to insert ones own rules _above_ the logging rules and leave some more free lines in the script there so users really see it. > # Log invalid packets from DROP policy: > if [ -n "$LOGGING" ] ; then > ${IPTABLES} -A INPUT -d 255.255.255.255 -j DROP # do not log broadcasts > ${IPTABLES} -A INPUT -d 224.0.0.0/8 -j DROP # do not log Microsoft multicasts Why don't you just do the above always? Do just logging when we want logging. > ${IPTABLES} -A INPUT -m limit --limit 3/minute --limit-burst 3 -j LOG --log-prefix "INPUT policy: " > ${IPTABLES} -A OUTPUT -m limit --limit 3/minute --limit-burst 3 -j LOG --log-prefix "OUTPUT policy: " > ${IPTABLES} -A FORWARD -m limit --limit 3/minute --limit-burst 3 -j LOG --log-prefix "FORWARD policy: " > fi Logging are long enough, maybe just shorten the logging prefix to "FW-IN: ", "FW-OUT: " and "FW-FWD: ". Just my own preference YMMV. -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |