View Single Post

  #3 (permalink)  
Old 06-04-2004
ynotssor
 
Posts: n/a
Default Re: How to read firewall logs?

"Mike Oliver" <mike_lists@verizon.net> wrote in message
news:2ibrslFk3d32U1@uni-berlin.de

> OK, so I finally got around to having iptables LOG and then DROP
> uninvited input packets, rather than just DROPping them. I didn't
> expect the volume to be quite that high! Seems people are attacking
> -- or at least sending SYN packets -- every few seconds.
>
> How do I figure out just what is being attempted? I can trace
> the SRC field with the "host" command, but what are TTL, ID,
> SPT, DPT, WINDOW, URGP?


http://logi.cc/linux/netfilter-log-format.php3

--
use hotmail for email replies
Reply With Quote