From bkoeller@u.washington.edu Thu Jan 11 16:51:20 2001 Received: from jason03.u.washington.edu (jason03.u.washington.edu [140.142.8.11]) by lists.u.washington.edu (8.9.3+UW00.05/8.9.3+UW00.12) with ESMTP id QAA85358 for ; Thu, 11 Jan 2001 16:51:18 -0800 Received: from dante09.u.washington.edu (bkoeller@dante09.u.washington.edu [140.142.15.19]) by jason03.u.washington.edu (8.9.3+UW00.05/8.9.3+UW00.12) with ESMTP id QAA39074 for ; Thu, 11 Jan 2001 16:51:17 -0800 Received: from localhost (bkoeller@localhost) by dante09.u.washington.edu (8.9.3+UW00.05/8.9.3+UW00.12) with ESMTP id QAA131634 for ; Thu, 11 Jan 2001 16:51:16 -0800 Date: Thu, 11 Jan 2001 16:51:16 -0800 (PST) From: "B. Koeller" To: UW Linux Group Subject: Re: Log TCP and UDP connections In-Reply-To: Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Or even easier...you can use ippl (which I think stands for ip port logger). One quick rpm (if you use a distro w/rpm), and one config file. Thanks. Brandon Koeller Emersons' Law of Contrariness: Our chief want in life is somebody who shall make us do what we can. Having found them, we shall then hate them for it. On Tue, 19 Dec 2000, Lawrence Lin wrote: |On Tue, 19 Dec 2000, Mike wrote: | |> You can log udp/tcp connection attempts (but not some scan types) using |> kernel filtering with 'ipchains' or 'iptables'. | |PMFirewall[1] with Logcheck[2] is a good combo. PMFirewall is easy to use |(though you can muck around the config files if you choose) and Logcheck |cuts through your logs to present the important stuff. | |Portsentry[3] is also neat. | |[1]: http://www.pointman.org/ |[2]: http://www.psionic.com/abacus/logcheck/ |[3]: http://www.psionic.com/abacus/portsentry/ | |[2048/1024 bit DH/DSS ] |Key ID: 0xF1B44F9D |http://students.washington.edu/llin/ | | | .