From llin@u.washington.edu Tue Dec 19 14:00:15 2000 Received: from jason02.u.washington.edu (root@jason02.u.washington.edu [140.142.8.52]) by lists.u.washington.edu (8.9.3+UW00.05/8.9.3+UW00.12) with ESMTP id OAA361004 for ; Tue, 19 Dec 2000 14:00:14 -0800 Received: from dante26.u.washington.edu (llin@dante26.u.washington.edu [140.142.15.81]) by jason02.u.washington.edu (8.9.3+UW00.05/8.9.3+UW00.12) with ESMTP id OAA42262 for ; Tue, 19 Dec 2000 14:00:13 -0800 Received: from localhost (llin@localhost) by dante26.u.washington.edu (8.9.3+UW00.05/8.9.3+UW00.12) with ESMTP id OAA104472 for ; Tue, 19 Dec 2000 14:00:12 -0800 Date: Tue, 19 Dec 2000 14:00:12 -0800 (PST) From: Lawrence Lin To: UW Linux Group Subject: Re: Log TCP and UDP connections In-Reply-To: Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII On Tue, 19 Dec 2000, Mike wrote: > You can log udp/tcp connection attempts (but not some scan types) using > kernel filtering with 'ipchains' or 'iptables'. PMFirewall[1] with Logcheck[2] is a good combo. PMFirewall is easy to use (though you can muck around the config files if you choose) and Logcheck cuts through your logs to present the important stuff. Portsentry[3] is also neat. [1]: http://www.pointman.org/ [2]: http://www.psionic.com/abacus/logcheck/ [3]: http://www.psionic.com/abacus/portsentry/ [2048/1024 bit DH/DSS ] Key ID: 0xF1B44F9D http://students.washington.edu/llin/ .