From mboxrd@z Thu Jan 1 00:00:00 1970 From: Ted Kaczmarek Subject: Chain Policy DROP versus ACCEPT and logging Date: Sun, 12 Oct 2003 10:00:20 -0400 Sender: netfilter-admin@lists.netfilter.org Message-ID: <1065967220.5801.10.camel@tarkus> Reply-To: tedkaz@optonline.net Mime-Version: 1.0 Content-Transfer-Encoding: 7BIT Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: netfilter@lists.netfilter.org I have seen many setups where the default CHAIN Policy is to accept packets by default versus dropping them. >From my perspective a firewall should implicitly deny everything, hence INPUT and FORWARD should be DROP. Then rules are put in to allow what you want. But, one seems to lose some logging capabilities with such a setup. Is their a way to log the default INPUT and FORWARD policies for dropped packets with them set to DROP as opposed to having them set to ACCEPT and putting in logs for any deny rules. Thanks, Ted