Author Topic: How to check firewall log?  (Read 2256 times)

akong

  • Zen Apprentice
  • *
  • Posts: 18
  • Karma: +0/-0
    • View Profile
How to check firewall log?
« on: December 10, 2008, 06:39:10 am »
I want know the firewall function.
But I can't view some logs on queue logs.
It's firewall logs always clean.
Please tell me how to settings firewall logs.
Thanks a lot.

Javier Amor Garcia

  • Zentyal Staff
  • Zen Hero
  • *****
  • Posts: 1225
  • Karma: +12/-0
    • View Profile
Re: How to check firewall log?
« Reply #1 on: December 10, 2008, 09:37:03 am »
Hi,
 in order to activate the firewall log you ust do two tings:
 - activate the logs module (in Module Status section)
 - configure the logs and activate the firewall logs. Those are disabled by ddefault because they became huge in short time.

Rememeber that only are logged the rejected packets and the LOG targets.

Cheers,
  Javier

akong

  • Zen Apprentice
  • *
  • Posts: 18
  • Karma: +0/-0
    • View Profile
Re: How to check firewall log?
« Reply #2 on: December 10, 2008, 10:21:54 am »
OK,
I have enabled logs modules.
And I have enabled follow function
Events-->Log observer-->Configure-->Firewall-->Action then click enabled and save change
Events-->Log observer-->Configure-->Firewall-->Filter-->Add new
I only choose events to any and click add.
Then I click save changes to apply settings.
I click Logs section and click queue logs.
I can't found some logs.
Is it all right?

Javier Amor Garcia

  • Zentyal Staff
  • Zen Hero
  • *****
  • Posts: 1225
  • Karma: +12/-0
    • View Profile
Re: How to check firewall log?
« Reply #3 on: December 10, 2008, 10:25:31 am »
You don;t need to configure a observer to see whether the firewall logs are working. Go to Logs->Query Logs and select the firewall module.
You hsould see some lines there.

akong

  • Zen Apprentice
  • *
  • Posts: 18
  • Karma: +0/-0
    • View Profile
Re: How to check firewall log?
« Reply #4 on: December 10, 2008, 10:43:58 am »
So,if I want log.
Must I set block rule and add new LOG rule?
Could you tell me step by step to study?

Javier Amor Garcia

  • Zentyal Staff
  • Zen Hero
  • *****
  • Posts: 1225
  • Karma: +12/-0
    • View Profile
Re: How to check firewall log?
« Reply #5 on: December 10, 2008, 10:47:22 am »
Ok, only two things are logged:
 - packets with are blocked
 - packet which have a LOG rule

So to see if its works the easier way is to hit the eBox with a traffic you know for sure it will be blocked

akong

  • Zen Apprentice
  • *
  • Posts: 18
  • Karma: +0/-0
    • View Profile
Re: How to check firewall log?
« Reply #6 on: December 11, 2008, 01:55:32 am »
So,
Is like a follow settings?

LOG       any      eBox ssh       --      
DENY    any    eBox ssh    --    
LOG            any   eBox administration    --    
DENY    any    eBox administration    --