From mboxrd@z Thu Jan 1 00:00:00 1970 From: Aleksandar Milivojevic Subject: Re: logging -- a newbie question Date: Fri, 07 May 2004 09:19:56 -0500 Sender: netfilter-admin@lists.netfilter.org Message-ID: <409B9B0C.8090207@pbl.ca> References: <20040507133419.GA32666@bofh.rus.uni-stuttgart.de> <200405071445.38711.Antony@Soft-Solutions.co.uk> <20040507140437.GB32666@bofh.rus.uni-stuttgart.de> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <20040507140437.GB32666@bofh.rus.uni-stuttgart.de> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii"; format="flowed" To: Pawel Mueller Cc: netfilter@lists.netfilter.org Pawel Mueller wrote: > I didn't meant the LOG target. There must be a file where all > connections are listed. I know, because I saw it once. But it was a half > year ago, so I can't remember. I know I read it in a howto. It was one > that described, how you can debuge a firewall and it mentioned a file, > where you can see the hole ACK, SYN and ESTABLISHED or DROPED stuff for > each package (I think) that passes the firewall. AFAIK, no such thing. "netstat -a" will show you states of current connections to/from local machine. tcpdump is your friend while debugging firewalls. -- Aleksandar Milivojevic Pollard Banknote Limited Systems Administrator 1499 Buffalo Place Tel: (204) 474-2323 ext 276 Winnipeg, MB R3T 1L7