RE: lug-bg: MRTG and IPCHAINS problem

2002-03-28 Thread Boyan Krosnov

> -Original Message-
> From: Vasil Kolev [mailto:[EMAIL PROTECTED]] 
> Sent: Thursday, March 28, 2002 11:31 AM
> To: [EMAIL PROTECTED]
> Subject: Re: lug-bg: MRTG and IPCHAINS problem
> 
> 
> Izvinqvam se che ne sledq thread-a, obache az ponezhe sum 
> pisal dosta podobni otchitaniq - da, tova s otchitaneto na 
> edin interface raboti. Az po princip go pravq taka ipchains 
> -I input -s usera -i eth1 ipchains -I output -d usera -i eth1 
> i mi vurshi rabota, dazhe na momenti ne se nalaga da se 
> polzva tova s -i eth1... napisal sum dazhe neshto - 
Horata vyzroptaha sreshtu forward s -i eth1 i za dwete posoki, koeto ne
bi trqbwalo da raboti.

BR,
Boyan
===
A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers)
http://www.linux-bulgaria.org/ Hosted by Internet Group Ltd. - Stara Zagora




Re: lug-bg: MRTG and IPCHAINS problem

2002-03-28 Thread Vasil Kolev

Izvinqvam se che ne sledq thread-a, obache az ponezhe sum pisal dosta
podobni otchitaniq - da, tova s otchitaneto na edin interface raboti. Az
po princip go pravq taka
ipchains -I input -s usera -i eth1
ipchains -I output -d usera -i eth1
i mi vurshi rabota, dazhe na momenti ne se nalaga da se polzva tova s
-i eth1... napisal sum dazhe neshto - http://ludost.net/chains/, koeto
se zanimava s otchitane - ne e napraveno da se polzva ot vseki, ima si
nuzhda ot dopipvane za specifichni nuzhni, no misle che ot readme-to mozhe
da se razbere osnovnata ideq i da se reshi takuv problem.

On Thu, 28 Mar 2002, Teodor Georgiev wrote:

> a?
> e kak taka i dvete na edin ethernet?
>
> - Original Message -
> From: "Marian Popov" <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Sent: Thursday, March 28, 2002 12:37 AM
> Subject: Re: lug-bg: MRTG and IPCHAINS problem
>
>
> > On Wed, 27 Mar 2002, Teodor Georgiev wrote:
> >
> > >
> > >
> > > iskash da ti otchita TRANZITNIA trafik.
> > >
> > > slozhi go na forward verigata.
> > >
> > > da rechem che i az imam :PC1, PC2, PC3 -> {gateway} -->
> > > (((internet)))
> > >
> > > iskash da otchitash INTERNET Trafika na vseko PC, a ne tozi ot PC-to do
> > > gateway'a,
> > > shtoto ako na gateway'a ima i mail server, togava shte im se otchita i
> tova
> > > na PC-tata.
> > >
> > > togava slagash forward chain na gateway i merish vsichko:
> > >
> > > ot : PC1|PC2|PC3
> > > kum : ! lokalnia subnet
> > >
> >
> >
> > Eto rule koito slojih
> >
> > ipchains -A forward -i eth1 -s CLIENT -d ! GATEWAY  -j ACCEPT
> > ipchains -A forward -i eth1 -s ! GATEWAY -d CLIENT  -j ACCEPT
> >
> > Pri tova polojenie poluchavam samo
> >
> > 0
> > 0
> >
> > I nishto poveche demek ne otchita nikakyv traffic.
> >

===
A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers)
http://www.linux-bulgaria.org/ Hosted by Internet Group Ltd. - Stara Zagora




Re: lug-bg: MRTG and IPCHAINS problem

2002-03-28 Thread Georgi Chorbadzhiyski

Marian Popov wrote:
> On Wed, 27 Mar 2002, Teodor Georgiev wrote:
> 
> 
>>
>>iskash da ti otchita TRANZITNIA trafik.
>>
>>slozhi go na forward verigata.
>>
>>da rechem che i az imam :PC1, PC2, PC3 -> {gateway} -->
>>(((internet)))
>>
>>iskash da otchitash INTERNET Trafika na vseko PC, a ne tozi ot PC-to do
>>gateway'a,
>>shtoto ako na gateway'a ima i mail server, togava shte im se otchita i tova
>>na PC-tata.
>>
>>togava slagash forward chain na gateway i merish vsichko:
>>
>>ot : PC1|PC2|PC3
>>kum : ! lokalnia subnet
>>
> 
> 
> 
> Eto rule koito slojih
> 
> ipchains -A forward -i eth1 -s CLIENT -d ! GATEWAY  -j ACCEPT
> ipchains -A forward -i eth1 -s ! GATEWAY -d CLIENT  -j ACCEPT
> 
> Pri tova polojenie poluchavam samo
> 
> 0
> 0
> 
> I nishto poveche demek ne otchita nikakyv traffic.

aaa btw zabravih v predishniat post da napisha da mahnesh -i ethXX



===
A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers)
http://www.linux-bulgaria.org/ Hosted by Internet Group Ltd. - Stara Zagora




Re: lug-bg: MRTG and IPCHAINS problem

2002-03-28 Thread Teodor Georgiev

a?
e kak taka i dvete na edin ethernet?

- Original Message -
From: "Marian Popov" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Thursday, March 28, 2002 12:37 AM
Subject: Re: lug-bg: MRTG and IPCHAINS problem


> On Wed, 27 Mar 2002, Teodor Georgiev wrote:
>
> >
> >
> > iskash da ti otchita TRANZITNIA trafik.
> >
> > slozhi go na forward verigata.
> >
> > da rechem che i az imam :PC1, PC2, PC3 -> {gateway} -->
> > (((internet)))
> >
> > iskash da otchitash INTERNET Trafika na vseko PC, a ne tozi ot PC-to do
> > gateway'a,
> > shtoto ako na gateway'a ima i mail server, togava shte im se otchita i
tova
> > na PC-tata.
> >
> > togava slagash forward chain na gateway i merish vsichko:
> >
> > ot : PC1|PC2|PC3
> > kum : ! lokalnia subnet
> >
>
>
> Eto rule koito slojih
>
> ipchains -A forward -i eth1 -s CLIENT -d ! GATEWAY  -j ACCEPT
> ipchains -A forward -i eth1 -s ! GATEWAY -d CLIENT  -j ACCEPT
>
> Pri tova polojenie poluchavam samo
>
> 0
> 0
>
> I nishto poveche demek ne otchita nikakyv traffic.
>
>
>
> >
> >
> >
> >
> >
> >
> >
===
> > A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers)
> > http://www.linux-bulgaria.org/ Hosted by Internet Group Ltd. - Stara
Zagora
> >
>
> =-rw-r--r--===
> Pazardjik.com System Administrator
> email: [EMAIL PROTECTED]
> icq: 9362972
>
>
===
> A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers)
> http://www.linux-bulgaria.org/ Hosted by Internet Group Ltd. - Stara
Zagora
>

===
A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers)
http://www.linux-bulgaria.org/ Hosted by Internet Group Ltd. - Stara Zagora




Re: lug-bg: MRTG and IPCHAINS problem

2002-03-28 Thread Georgi Chorbadzhiyski

Marian Popov wrote:
> On Wed, 27 Mar 2002, Teodor Georgiev wrote:
> 
> 
>>
>>iskash da ti otchita TRANZITNIA trafik.
>>
>>slozhi go na forward verigata.
>>
>>da rechem che i az imam :PC1, PC2, PC3 -> {gateway} -->
>>(((internet)))
>>
>>iskash da otchitash INTERNET Trafika na vseko PC, a ne tozi ot PC-to do
>>gateway'a,
>>shtoto ako na gateway'a ima i mail server, togava shte im se otchita i tova
>>na PC-tata.
>>
>>togava slagash forward chain na gateway i merish vsichko:
>>
>>ot : PC1|PC2|PC3
>>kum : ! lokalnia subnet
>>
> 
> 
> 
> Eto rule koito slojih
> 
> ipchains -A forward -i eth1 -s CLIENT -d ! GATEWAY  -j ACCEPT
> ipchains -A forward -i eth1 -s ! GATEWAY -d CLIENT  -j ACCEPT
> 
> Pri tova polojenie poluchavam samo
> 
> 0
> 0
> 
> I nishto poveche demek ne otchita nikakyv traffic.

CLIENT="192.168.0.15"
LOCALNET="192.168.0.1/24"

ipchains -A forward -i eth0 -s $CLIENT -d ! $LOCALNET -j ACCEPT
  
ipchains -A forward -i eth0 -s ! $LOCALNET -d $CLIENT -j ACCEPT

vav forward ruleto ne se otchita trafika kam samiat server, zatova
nai-veroiatno wizhdash 0 ;)

http://support.imagestream.com/iptables_Firewall.html

Stava duma za IPTABLES no principa e sashtiat.

===
A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers)
http://www.linux-bulgaria.org/ Hosted by Internet Group Ltd. - Stara Zagora




RE: lug-bg: MRTG and IPCHAINS problem

2002-03-27 Thread Georgi Sinapov


> Eto rule koito slojih
> 
> ipchains -A forward -i eth1 -s CLIENT -d ! GATEWAY  -j ACCEPT
> ipchains -A forward -i eth1 -s ! GATEWAY -d CLIENT  -j ACCEPT
> 
> Pri tova polojenie poluchavam samo
> 
> 0
> 0
> 
> I nishto poveche demek ne otchita nikakyv traffic.
> 
A ne trqbwa li dwata rula da sa kym razli4ni eth karti, t.e. pyrwiqt da
e kym eth "nawyn", a wtoriqt kym eth w LAN-a?


Best e-gards,
Georgi Sinapov

===
A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers)
http://www.linux-bulgaria.org/ Hosted by Internet Group Ltd. - Stara Zagora




Re: lug-bg: MRTG and IPCHAINS problem

2002-03-27 Thread Marian Popov

On Wed, 27 Mar 2002, Teodor Georgiev wrote:

>
>
> iskash da ti otchita TRANZITNIA trafik.
>
> slozhi go na forward verigata.
>
> da rechem che i az imam :PC1, PC2, PC3 -> {gateway} -->
> (((internet)))
>
> iskash da otchitash INTERNET Trafika na vseko PC, a ne tozi ot PC-to do
> gateway'a,
> shtoto ako na gateway'a ima i mail server, togava shte im se otchita i tova
> na PC-tata.
>
> togava slagash forward chain na gateway i merish vsichko:
>
> ot : PC1|PC2|PC3
> kum : ! lokalnia subnet
>


Eto rule koito slojih

ipchains -A forward -i eth1 -s CLIENT -d ! GATEWAY  -j ACCEPT
ipchains -A forward -i eth1 -s ! GATEWAY -d CLIENT  -j ACCEPT

Pri tova polojenie poluchavam samo

0
0

I nishto poveche demek ne otchita nikakyv traffic.



>
>
>
>
>
>
> ===
> A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers)
> http://www.linux-bulgaria.org/ Hosted by Internet Group Ltd. - Stara Zagora
>

=-rw-r--r--===
Pazardjik.com System Administrator
email: [EMAIL PROTECTED]
icq: 9362972

===
A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers)
http://www.linux-bulgaria.org/ Hosted by Internet Group Ltd. - Stara Zagora




Re: lug-bg: MRTG and IPCHAINS problem

2002-03-27 Thread Teodor Georgiev


- Original Message -
From: "Marian Popov" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Tuesday, March 26, 2002 10:31 PM
Subject: Re: lug-bg: MRTG and IPCHAINS problem


> On Tue, 26 Mar 2002, Teodor Georgiev wrote:
> Poglednah kakvo ima v contrib no tam imashe script koito countvashe
> obshtia trafik na servera ili trafika samo na 1 ip i ne mojah da razbera
> kakvi parametri da mu dam za da mi pokazva traffic na mnogo ip adresi.

x.x.x.x/x ?

> Problema mi e che ne mi meri pravilno samia rule v ipchains i ne znam kyde
> gresha. Otchita mi samo trafik ot server-a kym dadenoto IP i obratno. A az
> iskam da otchita vsichkia traffic na tova IP bez tozi ot servera demek
> obratnoto na tova koeto poluchavam.
>
> Oh chak i az se obyrkah veche ne znam dali si me razbral ama ako ne si
> kaji da obiasnia po-choveshki.
>
> mano
>


iskash da ti otchita TRANZITNIA trafik.

slozhi go na forward verigata.

da rechem che i az imam :PC1, PC2, PC3 -> {gateway} -->
(((internet)))

iskash da otchitash INTERNET Trafika na vseko PC, a ne tozi ot PC-to do
gateway'a,
shtoto ako na gateway'a ima i mail server, togava shte im se otchita i tova
na PC-tata.

togava slagash forward chain na gateway i merish vsichko:

ot : PC1|PC2|PC3
kum : ! lokalnia subnet







===
A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers)
http://www.linux-bulgaria.org/ Hosted by Internet Group Ltd. - Stara Zagora




Re: lug-bg: MRTG and IPCHAINS problem

2002-03-26 Thread Marian Popov

On Tue, 26 Mar 2002, Teodor Georgiev wrote:

>
> vmesto da preotkrivash toplata voda, v "contrib" direktoriata na MRTG si ima
> gotovi scriptove za
> ipchains i iptables accounting. Rabotiat perfektno.
> Na men MRTG mi vyrshi idealna rabota, dosega ne sum imal povod da se oplacha
> ot nego.

Poglednah kakvo ima v contrib no tam imashe script koito countvashe
obshtia trafik na servera ili trafika samo na 1 ip i ne mojah da razbera
kakvi parametri da mu dam za da mi pokazva traffic na mnogo ip adresi.

Kato naprimer moia script go pravi taka
root@wireless:/home/mrtg# ./statslan 61
183535
534741

root@wireless:/home/mrtg# ./statslan 62
29787
304126

I taka natatyk kato pod tezi cifri imam predvaritelno zadadeni IP-ta i
scripta mi vzima za vsiako IP po otdelno statistika.

Problema mi e che ne mi meri pravilno samia rule v ipchains i ne znam kyde
gresha. Otchita mi samo trafik ot server-a kym dadenoto IP i obratno. A az
iskam da otchita vsichkia traffic na tova IP bez tozi ot servera demek
obratnoto na tova koeto poluchavam.

Oh chak i az se obyrkah veche ne znam dali si me razbral ama ako ne si
kaji da obiasnia po-choveshki.

mano


>
> a probva li s forward? ;)
>
> - Original Message -
> From: "Marian Popov" <[EMAIL PROTECTED]>
> To: <[EMAIL PROTECTED]>
> Sent: Tuesday, March 26, 2002 2:01 AM
> Subject: lug-bg: MRTG and IPCHAINS problem
>
>
> > Hello, grupa.
> >
> > Sigurno na niakoi ot vas im e pisnalo ot MRTG no poneje ne mojah da
> > nameria reshenie na moia problem v tyrsachkata na site-a reshih da postvam
> > kakto se kazva.
> >
> > Ta nabyrzo estestvoto na problema.
> >
> > Imam edna mashina s niakolko LAN karti na vsiaka ot koito imam routirani
> > otdelni grupi ot ip adresi.
> >
> > Imam MRTG i s IPCHAINS se opitvam da vzimam stoinosti za IN i OUT trafik
> > za vsiako IP po otdelno.
> >
> > Problemyt m ie tam che se otchita trafika edinstveno ako dadenia ip adres
> > izteglia ili predava informacia na servera, koito mu se iaviava i GW i
> > kydeto e pusnato i MRTG-to.
> >
> > Ot druga mashina puskam ping kym tova IP i gledam stoinostite no te ne
> > pomrydvat. Kokato pusna ping obache ot tazi mashina na koiato e MRTG-to
> > sichko e pushka i stoinostite se natrupvat.
> >
> > Niamam drugi verigi na tazi mashina osven tezi za MRTG.
> >
> > Eto i nachinite po, koito se opitvam da logvam traffika.
> >
> > ipchains -A input  -i eth1 -s 212.116.10.10 -d 0/0  -j ACCEPT
> > ipchains -A output -i eth1 -s 0/0 -d 212.116.10.10  -j ACCEPT
> >
> >
> > I eto i drugia metod kydeto efekta e syshtia.
> >
> > ipchains -A input  -i eth1 -d 212.116.10.10 -s ! 212.116.10.10  -j ACCEPT
> > ipchains -A output -i eth1 -s 212.116.10.10 -d ! 212.116.10.10  -j ACCEPT
> >
> >
> > Pak povtariam trafika se otchita SAMO kogato dadenoto IP obmenia
> > informacia s kompiutera na koito e pusnato MRTG-to
> >
> >
> > Priemam vsiakakvi predlojenia.
> >
> >
> > =-rw-r--r--===
> > Pazardjik.com System Administrator
> > email: [EMAIL PROTECTED]
> > icq: 9362972
> >
> >
> ===
> > A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers)
> > http://www.linux-bulgaria.org/ Hosted by Internet Group Ltd. - Stara
> Zagora
>
> ===
> A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers)
> http://www.linux-bulgaria.org/ Hosted by Internet Group Ltd. - Stara Zagora
>

=-rw-r--r--===
Pazardjik.com System Administrator
email: [EMAIL PROTECTED]
icq: 9362972

===
A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers)
http://www.linux-bulgaria.org/ Hosted by Internet Group Ltd. - Stara Zagora




Re: lug-bg: MRTG and IPCHAINS problem

2002-03-26 Thread Marian Popov

On Tue, 26 Mar 2002, Radoslav Kolev wrote:

> Marian Popov wrote:
>
> >ipchains -A input  -i eth1 -d 212.116.10.10 -s ! 212.116.10.10  -j ACCEPT
> >ipchains -A output -i eth1 -s 212.116.10.10 -d ! 212.116.10.10  -j ACCEPT
> >
> ipchains -A input  -i eth1 -s 212.116.10.10 -d 0/0  -j ACCEPT
> ipchains -A output -i eth1 -s 0/0 -d 212.116.10.10  -j ACCEPT
>
> Zdrasti mano!
> Tva IP 212.116.10.10 IP-to na gateway-to li e? Ako e taka, to neshtata
> rabotioat tochno kakto si triabva.
> Meri ti trafika ot i kam routera. Pone az po drug nachin ne moga da si
> obiasnia tozi rezultat. Tova IP triabva da ti e IPto na koeto iskash da
> mu merish trafika. Inache v ipchains paketa minava po chainovete taka,
> ako pristigne ot vat -->input-->forward-->output, v sluchaj che se
> routira, i ne e sazdaden ot routera ili da e prednaznachen za nego. Za
> razlika ot tova v 2.4 netfilter ako se forwardva minava samo prez
> forward verigata.

Ne, tova e IP-to koeto iskam da countvam.
Da rechem che ip-to na gw e 212.116.10.1

Tova znachi li che triabva da go pravia s forward a ne s input i output ?


>
> RAdo
>
>
>
>
> ===
> A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers)
> http://www.linux-bulgaria.org/ Hosted by Internet Group Ltd. - Stara Zagora
>

=-rw-r--r--===
Pazardjik.com System Administrator
email: [EMAIL PROTECTED]
icq: 9362972

===
A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers)
http://www.linux-bulgaria.org/ Hosted by Internet Group Ltd. - Stara Zagora




Re: lug-bg: MRTG and IPCHAINS problem

2002-03-26 Thread Radoslav Kolev

Marian Popov wrote:

>ipchains -A input  -i eth1 -d 212.116.10.10 -s ! 212.116.10.10  -j ACCEPT
>ipchains -A output -i eth1 -s 212.116.10.10 -d ! 212.116.10.10  -j ACCEPT
>
ipchains -A input  -i eth1 -s 212.116.10.10 -d 0/0  -j ACCEPT
ipchains -A output -i eth1 -s 0/0 -d 212.116.10.10  -j ACCEPT

Zdrasti mano!
Tva IP 212.116.10.10 IP-to na gateway-to li e? Ako e taka, to neshtata 
rabotioat tochno kakto si triabva.
Meri ti trafika ot i kam routera. Pone az po drug nachin ne moga da si 
obiasnia tozi rezultat. Tova IP triabva da ti e IPto na koeto iskash da 
mu merish trafika. Inache v ipchains paketa minava po chainovete taka, 
ako pristigne ot vat -->input-->forward-->output, v sluchaj che se 
routira, i ne e sazdaden ot routera ili da e prednaznachen za nego. Za 
razlika ot tova v 2.4 netfilter ako se forwardva minava samo prez 
forward verigata.

RAdo




===
A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers)
http://www.linux-bulgaria.org/ Hosted by Internet Group Ltd. - Stara Zagora




Re: lug-bg: MRTG and IPCHAINS problem

2002-03-25 Thread Teodor Georgiev


vmesto da preotkrivash toplata voda, v "contrib" direktoriata na MRTG si ima
gotovi scriptove za
ipchains i iptables accounting. Rabotiat perfektno.
Na men MRTG mi vyrshi idealna rabota, dosega ne sum imal povod da se oplacha
ot nego.

a probva li s forward? ;)

- Original Message -
From: "Marian Popov" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Tuesday, March 26, 2002 2:01 AM
Subject: lug-bg: MRTG and IPCHAINS problem


> Hello, grupa.
>
> Sigurno na niakoi ot vas im e pisnalo ot MRTG no poneje ne mojah da
> nameria reshenie na moia problem v tyrsachkata na site-a reshih da postvam
> kakto se kazva.
>
> Ta nabyrzo estestvoto na problema.
>
> Imam edna mashina s niakolko LAN karti na vsiaka ot koito imam routirani
> otdelni grupi ot ip adresi.
>
> Imam MRTG i s IPCHAINS se opitvam da vzimam stoinosti za IN i OUT trafik
> za vsiako IP po otdelno.
>
> Problemyt m ie tam che se otchita trafika edinstveno ako dadenia ip adres
> izteglia ili predava informacia na servera, koito mu se iaviava i GW i
> kydeto e pusnato i MRTG-to.
>
> Ot druga mashina puskam ping kym tova IP i gledam stoinostite no te ne
> pomrydvat. Kokato pusna ping obache ot tazi mashina na koiato e MRTG-to
> sichko e pushka i stoinostite se natrupvat.
>
> Niamam drugi verigi na tazi mashina osven tezi za MRTG.
>
> Eto i nachinite po, koito se opitvam da logvam traffika.
>
> ipchains -A input  -i eth1 -s 212.116.10.10 -d 0/0  -j ACCEPT
> ipchains -A output -i eth1 -s 0/0 -d 212.116.10.10  -j ACCEPT
>
>
> I eto i drugia metod kydeto efekta e syshtia.
>
> ipchains -A input  -i eth1 -d 212.116.10.10 -s ! 212.116.10.10  -j ACCEPT
> ipchains -A output -i eth1 -s 212.116.10.10 -d ! 212.116.10.10  -j ACCEPT
>
>
> Pak povtariam trafika se otchita SAMO kogato dadenoto IP obmenia
> informacia s kompiutera na koito e pusnato MRTG-to
>
>
> Priemam vsiakakvi predlojenia.
>
>
> =-rw-r--r--===
> Pazardjik.com System Administrator
> email: [EMAIL PROTECTED]
> icq: 9362972
>
>
===
> A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers)
> http://www.linux-bulgaria.org/ Hosted by Internet Group Ltd. - Stara
Zagora

===
A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers)
http://www.linux-bulgaria.org/ Hosted by Internet Group Ltd. - Stara Zagora




lug-bg: MRTG and IPCHAINS problem

2002-03-25 Thread Marian Popov

Hello, grupa.

Sigurno na niakoi ot vas im e pisnalo ot MRTG no poneje ne mojah da
nameria reshenie na moia problem v tyrsachkata na site-a reshih da postvam
kakto se kazva.

Ta nabyrzo estestvoto na problema.

Imam edna mashina s niakolko LAN karti na vsiaka ot koito imam routirani
otdelni grupi ot ip adresi.

Imam MRTG i s IPCHAINS se opitvam da vzimam stoinosti za IN i OUT trafik
za vsiako IP po otdelno.

Problemyt m ie tam che se otchita trafika edinstveno ako dadenia ip adres
izteglia ili predava informacia na servera, koito mu se iaviava i GW i
kydeto e pusnato i MRTG-to.

Ot druga mashina puskam ping kym tova IP i gledam stoinostite no te ne
pomrydvat. Kokato pusna ping obache ot tazi mashina na koiato e MRTG-to
sichko e pushka i stoinostite se natrupvat.

Niamam drugi verigi na tazi mashina osven tezi za MRTG.

Eto i nachinite po, koito se opitvam da logvam traffika.

ipchains -A input  -i eth1 -s 212.116.10.10 -d 0/0  -j ACCEPT
ipchains -A output -i eth1 -s 0/0 -d 212.116.10.10  -j ACCEPT


I eto i drugia metod kydeto efekta e syshtia.

ipchains -A input  -i eth1 -d 212.116.10.10 -s ! 212.116.10.10  -j ACCEPT
ipchains -A output -i eth1 -s 212.116.10.10 -d ! 212.116.10.10  -j ACCEPT


Pak povtariam trafika se otchita SAMO kogato dadenoto IP obmenia
informacia s kompiutera na koito e pusnato MRTG-to


Priemam vsiakakvi predlojenia.


=-rw-r--r--===
Pazardjik.com System Administrator
email: [EMAIL PROTECTED]
icq: 9362972

===
A mail-list of Linux Users Group - Bulgaria (bulgarian linuxers)
http://www.linux-bulgaria.org/ Hosted by Internet Group Ltd. - Stara Zagora