Hola Arturo, muchas gracias por tu ayuda. Es verdad que hay cadenas de
usuarios, las saque de un script de un tutorial de Frozentux. Lo que decis
es verdad, yo creo cadenas de usuario y luego en la caden de INPUT las
utilizo con "-j accept". Te adjunto la parte principal del script y te
agradezco mucho desde ya. Saludos.
Alejandro


----- Original Message ----- 
From: "Arturo 'Buanzo' Busleiman" <[EMAIL PROTECTED]>
To: "Alejandro Kurchis" <[EMAIL PROTECTED]>; "Lista de temas
generales del LUGAr y de Linux" <[email protected]>
Sent: Monday, December 27, 2004 11:24 AM
Subject: Re: [LUGAr-gral] LOG en iptables con 0 bytes


> Alejandro Kurchis wrote:
> > $IPTABLES -A tcp_packets -p TCP -s 0/0 --dport 22 -j LOG --log-level
> > INFO --log-prefix "SSH Access:"
> > $IPTABLES -A tcp_packets -p TCP -s 0/0 --dport 22 -j allowed
> > Como puedo hacer para que se logueen los ingresos ssh ??? Esta mal el
orden
> > o algo por el estilo ???
>
> No queres mandar el script de firewall? Estas usando cadenas creadas por
el usuario, -N, y eso no me
> indica nada. PERO el orden esta bien... primero el LOG, que hace
"continue" una vez trigeada, y
> despues la de accept.
>
> -- 
> Arturo "Buanzo" Busleiman - www.buanzo.com.ar - GNU/Linux Documentation
> President, Open Information System Security Group - Argentina
>
> In the darkest night, If my memory serves me right, I'll never turn back
> time, Forgetting you, but not the time (Green Day, Whatsername)
>
>
# 4. Rules set up.

# 4.1 Filter table

# 4.1.1 Set policies y FLUSH de las cadenas y tablas

$IPTABLES -P INPUT DROP
$IPTABLES -P OUTPUT DROP
$IPTABLES -P FORWARD DROP

$IPTABLES -F INPUT
$IPTABLES -F OUTPUT
$IPTABLES -F FORWARD
$IPTABLES -F -t nat
$IPTABLES -X

# Reset all IPTables counters

$IPTABLES -Z

# 4.1.2 Create userspecified chains

# Create chain for bad tcp packets

$IPTABLES -N bad_tcp_packets

# Create separate chains for ICMP, TCP and UDP to traverse

$IPTABLES -N allowed
$IPTABLES -N tcp_packets
$IPTABLES -N udp_packets
$IPTABLES -N icmp_packets

# 4.1.3 Create content in userspecified chains

# bad_tcp_packets chain

$IPTABLES -A bad_tcp_packets -p tcp --tcp-flags SYN,ACK SYN,ACK -m state 
--state NEW -j REJECT --reject-with tcp-reset 
$IPTABLES -A bad_tcp_packets -p tcp ! --syn -m state --state NEW -j LOG -
-log-prefix "New not syn:"
$IPTABLES -A bad_tcp_packets -p tcp ! --syn -m state --state NEW -j DROP

# allowed chain

$IPTABLES -A allowed -p TCP --syn -j ACCEPT
$IPTABLES -A allowed -p TCP -m state --state ESTABLISHED,RELATED -j 
ACCEPT
$IPTABLES -A allowed -p TCP -j DROP

# tcp_packets chain

# El port 22 me habilita mi SSH Server para ser accedido desde todos lados
# El port 8245 es para uso del cliente DNS Dinamico noip

#$IPTABLES -A tcp_packets -p TCP -s 0/0 --dport 21 -j allowed
$IPTABLES -A tcp_packets -p TCP -s 0/0 --dport 22 -j LOG --log-level INFO 
--log-prefix "SSH Access:"
$IPTABLES -A tcp_packets -p TCP -s 0/0 --dport 22 -j allowed
$IPTABLES -A tcp_packets -p TCP -s 0/0 --dport 8245 -j allowed
#$IPTABLES -A tcp_packets -p TCP -s 0/0 --dport 80 -j allowed
#$IPTABLES -A tcp_packets -p TCP -s 0/0 --dport 113 -j allowed

# udp_packets chain

#$IPTABLES -A udp_packets -p UDP -s 0/0 --destination-port 53 -j ACCEPT
#$IPTABLES -A udp_packets -p UDP -s 0/0 --destination-port 123 -j ACCEPT
#$IPTABLES -A udp_packets -p UDP -s 0/0 --destination-port 2074 -j ACCEPT
#$IPTABLES -A udp_packets -p UDP -s 0/0 --destination-port 4000 -j ACCEPT
#$IPTABLES -A udp_packets -p UDP -s 0/0 -j ACCEPT

# In Microsoft Networks you will be swamped by broadcasts. These lines 
# will prevent them from showing up in the logs.

$IPTABLES -A udp_packets -p UDP -i $INET_IFACE --destination-port 135:139 
-j DROP

# If we get DHCP requests from the Outside of our network, our logs will 
# be swamped as well. This rule will block them from getting logged.

$IPTABLES -A udp_packets -p UDP -i $INET_IFACE -d 255.255.255.255 --
destination-port 67:68 -j DROP

# icmp_packets chain

# Type=0 (echo reply); Type=3 (unreachable); Type=8 (echo request); 
Type=11 (time exceeded)

$IPTABLES -A icmp_packets -p ICMP -s 0/0 --icmp-type 8 -j ACCEPT
$IPTABLES -A icmp_packets -p ICMP -s 0/0 --icmp-type 30 -j ACCEPT

# 4.1.4 INPUT chain

# Bad TCP packets we don't want.

$IPTABLES -A INPUT -p tcp -j bad_tcp_packets

# Rules for special networks not part of the Internet Proteccion contra 
# el spoofing

$IPTABLES -A INPUT -p ALL -i $LAN_IFACE -s $LAN_IP_RANGE -j ACCEPT
$IPTABLES -A INPUT -p ALL -i $LO_IFACE -s $LO_IP -j ACCEPT

# Rules for incoming packets from the Internet.

$IPTABLES -A INPUT -p ALL -i $INET_IFACE -m state --state 
ESTABLISHED,RELATED -j ACCEPT
$IPTABLES -A INPUT -p TCP -i $INET_IFACE -j tcp_packets
$IPTABLES -A INPUT -p UDP -i $INET_IFACE -j udp_packets
$IPTABLES -A INPUT -p ICMP -i $INET_IFACE -j icmp_packets

-- 
Para desuscribirte ten�s que visitar la p�gina
https://listas.linux.org.ar/mailman/listinfo/lugar-gral/

/* Publica y encontra trabajo relacionado con softlibre en 
http://www.linux.org.ar/modules/jobs/ */

Si ten�s alg�n inconveniente o consulta escrib� a mailto:[EMAIL PROTECTED]

Responder a