2004-02-14 19:06:39 +01:00
|
|
|
<?xml version="1.0" encoding="UTF-8"?>
|
2008-07-07 22:42:54 +02:00
|
|
|
<!DOCTYPE article PUBLIC "-//OASIS//DTD DocBook XML V4.4//EN"
|
|
|
|
"http://www.oasis-open.org/docbook/xml/4.4/docbookx.dtd">
|
2004-02-14 19:06:39 +01:00
|
|
|
<article id="IPIP">
|
|
|
|
<!--$Id$-->
|
|
|
|
|
|
|
|
<articleinfo>
|
|
|
|
<title>Shorewall Logging</title>
|
|
|
|
|
|
|
|
<authorgroup>
|
|
|
|
<author>
|
|
|
|
<firstname>Tom</firstname>
|
|
|
|
|
|
|
|
<surname>Eastep</surname>
|
|
|
|
</author>
|
|
|
|
</authorgroup>
|
|
|
|
|
2006-07-07 03:04:16 +02:00
|
|
|
<pubdate><?dbtimestamp format="Y/m/d"?></pubdate>
|
2004-02-14 19:06:39 +01:00
|
|
|
|
|
|
|
<copyright>
|
2009-02-28 04:45:43 +01:00
|
|
|
<year>2001 - 2009</year>
|
2004-02-14 19:06:39 +01:00
|
|
|
|
|
|
|
<holder>Thomas M. Eastep</holder>
|
|
|
|
</copyright>
|
|
|
|
|
|
|
|
<legalnotice>
|
|
|
|
<para>Permission is granted to copy, distribute and/or modify this
|
|
|
|
document under the terms of the GNU Free Documentation License, Version
|
|
|
|
1.2 or any later version published by the Free Software Foundation; with
|
|
|
|
no Invariant Sections, with no Front-Cover, and with no Back-Cover
|
|
|
|
Texts. A copy of the license is included in the section entitled
|
2004-12-28 18:25:25 +01:00
|
|
|
<quote><ulink url="GnuCopyright.htm">GNU Free Documentation
|
|
|
|
License</ulink></quote>.</para>
|
2004-02-14 19:06:39 +01:00
|
|
|
</legalnotice>
|
|
|
|
</articleinfo>
|
|
|
|
|
2005-10-10 19:22:21 +02:00
|
|
|
<caution>
|
2009-02-28 04:45:43 +01:00
|
|
|
<para><emphasis role="bold">This article applies to Shorewall 4.3 and
|
2005-10-10 19:22:21 +02:00
|
|
|
later. If you are running a version of Shorewall earlier than Shorewall
|
2009-02-28 04:45:43 +01:00
|
|
|
4.3.5 then please see the documentation for that
|
2005-10-10 19:22:21 +02:00
|
|
|
release.</emphasis></para>
|
|
|
|
</caution>
|
|
|
|
|
2007-06-29 00:06:10 +02:00
|
|
|
<section id="Log">
|
2004-02-14 19:06:39 +01:00
|
|
|
<title>How to Log Traffic Through a Shorewall Firewall</title>
|
|
|
|
|
|
|
|
<para>The disposition of packets entering a Shorewall firewall is
|
|
|
|
determined by one of a number of Shorewall facilities. Only some of these
|
|
|
|
facilities permit logging.</para>
|
|
|
|
|
|
|
|
<orderedlist>
|
|
|
|
<listitem>
|
2008-08-15 07:03:24 +02:00
|
|
|
<para>The packet is part of an established connection. While the
|
2005-10-10 19:22:21 +02:00
|
|
|
packet can be logged using LOG rules in the ESTABLISHED section of
|
2007-08-03 00:09:56 +02:00
|
|
|
<ulink
|
|
|
|
url="manpages/shorewall-rules.html">/etc/shorewall/rules</ulink>, that
|
|
|
|
is not recommended because of the large amount of information that may
|
|
|
|
be logged.</para>
|
2004-02-14 19:06:39 +01:00
|
|
|
</listitem>
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
<para>The packet represents a connection request that is related to an
|
|
|
|
established connection (such as a <ulink url="FTP.html">data
|
|
|
|
connection associated with an FTP control connection</ulink>). These
|
2005-10-10 19:22:21 +02:00
|
|
|
packets may be logged using LOG rules in the RELATED section of <ulink
|
2007-07-04 02:18:10 +02:00
|
|
|
url="manpages/shorewall-rules.html">/etc/shorewall/rules</ulink>.</para>
|
2004-02-14 19:06:39 +01:00
|
|
|
</listitem>
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
<para>The packet is rejected because of an option in <ulink
|
2007-08-03 00:09:56 +02:00
|
|
|
url="manpages/shorewall.conf.html">/etc/shorewall/shorewall.conf</ulink>
|
|
|
|
or <ulink
|
2007-07-04 02:18:10 +02:00
|
|
|
url="manpages/shorewall-interfaces.html">/etc/shorewall/interfaces</ulink>.
|
2004-02-14 19:06:39 +01:00
|
|
|
These packets can be logged by setting the appropriate logging-related
|
2004-12-28 18:25:25 +01:00
|
|
|
option in <ulink
|
2007-07-04 02:23:43 +02:00
|
|
|
url="manpages/shorewall.conf.html">/etc/shorewall/shorewall.conf</ulink>.</para>
|
2004-02-14 19:06:39 +01:00
|
|
|
</listitem>
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
<para>The packet matches a rule in <ulink
|
2007-07-04 02:18:10 +02:00
|
|
|
url="manpages/shorewall-rules.html">/etc/shorewall/rules</ulink>. By
|
2004-02-14 19:06:39 +01:00
|
|
|
including a syslog level (see below) in the ACTION column of a rule
|
2005-09-12 20:43:26 +02:00
|
|
|
(e.g., <quote>ACCEPT<emphasis role="bold">:info</emphasis> net $FW tcp
|
2004-12-28 18:25:25 +01:00
|
|
|
22</quote>), the connection attempt will be logged at that
|
|
|
|
level.</para>
|
2004-02-14 19:06:39 +01:00
|
|
|
</listitem>
|
|
|
|
|
|
|
|
<listitem>
|
2004-12-28 18:25:25 +01:00
|
|
|
<para>The packet doesn't match a rule so it is handled by a policy
|
|
|
|
defined in <ulink
|
2007-08-03 00:09:56 +02:00
|
|
|
url="manpages/shorewall-policy.html">/etc/shorewall/policy</ulink>.
|
|
|
|
These may be logged by specifying a syslog level in the LOG LEVEL
|
|
|
|
column of the policy's entry (e.g., <quote>loc net ACCEPT <emphasis
|
2004-12-28 18:25:25 +01:00
|
|
|
role="bold">info</emphasis></quote>).</para>
|
2004-02-14 19:06:39 +01:00
|
|
|
</listitem>
|
|
|
|
</orderedlist>
|
|
|
|
</section>
|
|
|
|
|
2007-06-29 00:06:10 +02:00
|
|
|
<section id="Where">
|
2004-12-28 18:25:25 +01:00
|
|
|
<title>Where the Traffic is Logged and How to Change the
|
|
|
|
Destination</title>
|
2004-02-14 19:06:39 +01:00
|
|
|
|
2008-08-15 07:03:24 +02:00
|
|
|
<para>By default, Shorewall directs Netfilter to log using syslog (8).
|
2004-02-14 19:06:39 +01:00
|
|
|
Syslog classifies log messages by a <emphasis>facility</emphasis> and a
|
2004-12-28 18:25:25 +01:00
|
|
|
<emphasis>priority</emphasis> (using the notation
|
|
|
|
<emphasis>facility.priority</emphasis>).</para>
|
2004-02-14 19:06:39 +01:00
|
|
|
|
|
|
|
<para>The facilities defined by syslog are <emphasis>auth, authpriv, cron,
|
|
|
|
daemon, kern, lpr, mail, mark, news, syslog, user, uucp</emphasis> and
|
|
|
|
<emphasis>local0</emphasis> through <emphasis>local7.</emphasis></para>
|
|
|
|
|
|
|
|
<para>Throughout the Shorewall documentation, I will use the term
|
|
|
|
<emphasis>level</emphasis> rather than <emphasis>priority </emphasis>since
|
2008-08-15 07:03:24 +02:00
|
|
|
<emphasis>level</emphasis> is the term used by Netfilter. The syslog
|
2004-02-14 19:06:39 +01:00
|
|
|
documentation uses the term <emphasis>priority</emphasis>.</para>
|
|
|
|
|
2007-06-29 00:06:10 +02:00
|
|
|
<section id="Levels">
|
2004-02-14 19:06:39 +01:00
|
|
|
<title>Syslog Levels</title>
|
|
|
|
|
|
|
|
<para>Syslog levels are a method of describing to syslog (8) the
|
|
|
|
importance of a message. A number of Shorewall parameters have a syslog
|
|
|
|
level as their value.</para>
|
|
|
|
|
|
|
|
<para>Valid levels are:</para>
|
|
|
|
|
|
|
|
<simplelist>
|
|
|
|
<member>7 - <emphasis role="bold">debug</emphasis> (Debug-level
|
|
|
|
messages)</member>
|
|
|
|
|
2004-12-28 18:25:25 +01:00
|
|
|
<member>6 - <emphasis role="bold">info</emphasis>
|
|
|
|
(Informational)</member>
|
2004-02-14 19:06:39 +01:00
|
|
|
|
|
|
|
<member>5 - <emphasis role="bold">notice</emphasis> (Normal but
|
|
|
|
significant Condition)</member>
|
|
|
|
|
|
|
|
<member>4 - <emphasis role="bold">warning</emphasis> (Warning
|
|
|
|
Condition)</member>
|
|
|
|
|
2004-12-28 18:25:25 +01:00
|
|
|
<member>3 - <emphasis role="bold">err</emphasis> (Error
|
|
|
|
Condition)</member>
|
2004-02-14 19:06:39 +01:00
|
|
|
|
|
|
|
<member>2 - <emphasis role="bold">crit</emphasis> (Critical
|
|
|
|
Conditions)</member>
|
|
|
|
|
|
|
|
<member>1 - <emphasis role="bold">alert</emphasis> (must be handled
|
|
|
|
immediately)</member>
|
|
|
|
|
|
|
|
<member>0 - <emphasis role="bold">emerg</emphasis> (System is
|
|
|
|
unusable)</member>
|
|
|
|
</simplelist>
|
|
|
|
|
|
|
|
<para>For most Shorewall logging, a level of 6 (info) is appropriate.
|
2008-08-15 07:03:24 +02:00
|
|
|
Shorewall log messages are generated by Netfilter and are logged using
|
2004-02-14 19:06:39 +01:00
|
|
|
the <emphasis>kern</emphasis> facility and the level that you specify.
|
|
|
|
If you are unsure of the level to choose, 6 (info) is a safe bet. You
|
|
|
|
may specify levels by name or by number.</para>
|
|
|
|
|
2012-05-24 22:54:59 +02:00
|
|
|
<para>Beginning with Shorewall 4.5.5, the
|
|
|
|
<replaceable>level</replaceable> name or number may be optionally
|
|
|
|
followed by a comma-separated list of one or more<replaceable> log
|
|
|
|
options</replaceable>. The list is enclosed in parentheses. Log options
|
|
|
|
cause additional information to be included in each log message.</para>
|
|
|
|
|
|
|
|
<para>Valid log options are:</para>
|
|
|
|
|
|
|
|
<variablelist>
|
|
|
|
<varlistentry>
|
|
|
|
<term><emphasis role="bold">ip_options</emphasis></term>
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
<para>Log messages will include the option settings from the IP
|
|
|
|
header.</para>
|
|
|
|
</listitem>
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
<term><emphasis role="bold">macdecode</emphasis></term>
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
<para>Decode the MAC address and protocol.</para>
|
|
|
|
</listitem>
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
<term><emphasis role="bold">tcp_sequence</emphasis></term>
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
<para>Include TCP sequence numbers.</para>
|
|
|
|
</listitem>
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
<term><emphasis role="bold">tcp_options</emphasis></term>
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
<para>Include options from the TCP header.</para>
|
|
|
|
</listitem>
|
|
|
|
</varlistentry>
|
|
|
|
|
|
|
|
<varlistentry>
|
|
|
|
<term><emphasis role="bold">uid</emphasis></term>
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
<para>Include the UID of the sending program; only valid for
|
|
|
|
packets originating on the firewall itself.</para>
|
|
|
|
</listitem>
|
|
|
|
</varlistentry>
|
|
|
|
</variablelist>
|
|
|
|
|
|
|
|
<para>Example: <emphasis
|
|
|
|
role="bold">info(tcp_options,tcp_sequence)</emphasis></para>
|
|
|
|
|
2007-08-03 00:09:56 +02:00
|
|
|
<para>Syslogd writes log messages to files (typically in <filename
|
|
|
|
class="directory">/var/log/</filename>*) based on their facility and
|
|
|
|
level. The mapping of these facility/level pairs to log files is done in
|
|
|
|
/etc/syslog.conf (5). If you make changes to this file, you must restart
|
|
|
|
syslogd before the changes can take effect.</para>
|
2004-12-28 18:25:25 +01:00
|
|
|
|
|
|
|
<para>Syslog may also write to your system console. See <ulink
|
|
|
|
url="FAQ.htm#faq16">Shorewall FAQ 16</ulink> for ways to avoid having
|
|
|
|
Shorewall messages written to the console.</para>
|
2004-02-14 19:06:39 +01:00
|
|
|
</section>
|
|
|
|
|
2007-06-29 00:06:10 +02:00
|
|
|
<section id="ULOG">
|
2004-05-09 00:31:54 +02:00
|
|
|
<title>Configuring a Separate Log for Shorewall Messages (ulogd)</title>
|
2004-02-14 19:06:39 +01:00
|
|
|
|
|
|
|
<para>There are a couple of limitations to syslogd-based logging:</para>
|
|
|
|
|
|
|
|
<orderedlist>
|
|
|
|
<listitem>
|
2007-03-30 09:24:32 +02:00
|
|
|
<para>If you give, for example, kern.info its own log destination
|
2004-12-28 18:25:25 +01:00
|
|
|
then that destination will also receive all kernel messages of
|
|
|
|
levels 5 (notice) through 0 (emerg).</para>
|
2004-02-14 19:06:39 +01:00
|
|
|
</listitem>
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
<para>All kernel.info messages will go to that destination and not
|
2008-08-15 07:03:24 +02:00
|
|
|
just those from Netfilter.</para>
|
2004-02-14 19:06:39 +01:00
|
|
|
</listitem>
|
|
|
|
</orderedlist>
|
|
|
|
|
2009-02-28 04:45:43 +01:00
|
|
|
<para>If your kernel has ULOG target support (and most vendor-supplied
|
|
|
|
kernels do), you may also specify a log level of ULOG (must be all
|
|
|
|
caps). When ULOG is used, Shorewall will direct Netfilter to log the
|
|
|
|
related messages via the ULOG target which will send them to a process
|
|
|
|
called <quote>ulogd</quote>. The ulogd program is included in most
|
|
|
|
distributions and is also available from <ulink
|
2006-09-17 07:07:19 +02:00
|
|
|
url="http://www.netfilter.org/projects/ulogd/index.html">http://www.netfilter.org/projects/ulogd/index.html</ulink>.
|
2004-12-28 18:25:25 +01:00
|
|
|
Ulogd can be configured to log all Shorewall messages to their own log
|
2004-02-14 19:06:39 +01:00
|
|
|
file.</para>
|
|
|
|
|
|
|
|
<note>
|
2004-12-28 18:25:25 +01:00
|
|
|
<para>The ULOG logging mechanism is <emphasis
|
|
|
|
role="underline">completely separate</emphasis> from syslog. Once you
|
2007-08-03 00:09:56 +02:00
|
|
|
switch to ULOG, the settings in <filename>/etc/syslog.conf</filename>
|
|
|
|
have absolutely no effect on your Shorewall logging (except for
|
|
|
|
Shorewall status messages which still go to syslog).</para>
|
2004-02-14 19:06:39 +01:00
|
|
|
</note>
|
|
|
|
|
|
|
|
<para>You will need to change all instances of log levels (usually
|
2004-12-28 18:25:25 +01:00
|
|
|
<quote>info</quote>) in your Shorewall configuration files to
|
|
|
|
<quote>ULOG</quote> - this includes entries in the policy, rules and
|
2005-03-05 17:53:54 +01:00
|
|
|
shorewall.conf files. Here's what I had at one time:</para>
|
|
|
|
|
|
|
|
<programlisting>gateway:/etc/shorewall# grep -v ^\# * | egrep '\$LOG|ULOG|LOGFILE'
|
|
|
|
params:LOG=ULOG
|
|
|
|
policy:loc $FW REJECT $LOG
|
|
|
|
policy:net all DROP $LOG 10/sec:40
|
|
|
|
policy:all all REJECT $LOG
|
|
|
|
rules:REJECT:$LOG loc net tcp 25
|
|
|
|
rules:REJECT:$LOG loc net udp 1025:1031
|
|
|
|
rules:REJECT:$LOG dmz net udp 1025:1031
|
|
|
|
rules:ACCEPT:$LOG dmz net tcp 1024: 20
|
2005-09-12 20:43:26 +02:00
|
|
|
rules:REJECT:$LOG $FW net udp 1025:1031
|
2005-03-05 17:53:54 +01:00
|
|
|
shorewall.conf:LOGFILE=/var/log/shorewall
|
|
|
|
shorewall.conf:LOGUNCLEAN=$LOG
|
|
|
|
shorewall.conf:MACLIST_LOG_LEVEL=$LOG
|
|
|
|
shorewall.conf:TCP_FLAGS_LOG_LEVEL=$LOG
|
|
|
|
shorewall.conf:RFC1918_LOG_LEVEL=$LOG
|
|
|
|
gateway:/etc/shorewall# </programlisting>
|
2004-02-14 19:06:39 +01:00
|
|
|
|
2007-08-03 00:09:56 +02:00
|
|
|
<para>Finally edit <filename>/etc/shorewall/shorewall.conf</filename>
|
|
|
|
and set LOGFILE=<<emphasis>file that you wish to log
|
|
|
|
to</emphasis>>. This tells the <filename>/sbin/shorewall</filename>
|
|
|
|
program where to look for the log when processing its
|
|
|
|
<quote><command>show log</command></quote>,
|
|
|
|
<quote><command>logwatch</command></quote> and
|
|
|
|
<quote><command>dump</command></quote> commands.</para>
|
2008-02-10 06:22:39 +01:00
|
|
|
|
2009-02-28 04:45:43 +01:00
|
|
|
<para>The NFLOG target, a successor to ULOG, is supported shorewall.
|
|
|
|
Both ULOG and NFLOG may be followed by a list of up to three numbers in
|
2008-02-10 06:27:47 +01:00
|
|
|
parentheses.</para>
|
2008-02-10 06:22:39 +01:00
|
|
|
|
|
|
|
<itemizedlist>
|
|
|
|
<listitem>
|
|
|
|
<para>The first number specifies the netlink group (1-32). If
|
2008-02-10 06:27:47 +01:00
|
|
|
omitted (e.g., NFLOG(,0,10)) then a value of 1 is assumed.</para>
|
2008-02-10 06:22:39 +01:00
|
|
|
</listitem>
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
<para>The second number specifies the maximum number of bytes to
|
2008-02-10 06:27:47 +01:00
|
|
|
copy. If omitted, 0 (no limit) is assumed.</para>
|
2008-02-10 06:22:39 +01:00
|
|
|
</listitem>
|
|
|
|
|
|
|
|
<listitem>
|
|
|
|
<para>The third number specifies the number of log messages that
|
|
|
|
should be buffered in the kernel before they are sent to user space.
|
|
|
|
The default is 1.</para>
|
|
|
|
</listitem>
|
|
|
|
</itemizedlist>
|
|
|
|
|
|
|
|
<para>Examples:</para>
|
|
|
|
|
|
|
|
<para><filename>/etc/shorewall/shorewall.conf</filename>:
|
|
|
|
<programlisting>MACLIST_LOG_LEVEL=NFLOG(1,0,1)</programlisting></para>
|
|
|
|
|
|
|
|
<para><filename>/etc/shorewall/rules</filename>:<programlisting>#ACTION SOURCE DEST PROTO DEST
|
|
|
|
# PORT(S)
|
|
|
|
ACCEPT:NFLOG(1,0,1) vpn fw tcp ssh,time,631,8080 </programlisting></para>
|
2004-02-14 19:06:39 +01:00
|
|
|
</section>
|
|
|
|
</section>
|
|
|
|
|
2007-06-29 00:06:10 +02:00
|
|
|
<section id="Syslog-ng">
|
2004-02-14 19:06:39 +01:00
|
|
|
<title>Syslog-ng</title>
|
|
|
|
|
|
|
|
<para><ulink
|
2004-12-28 18:25:25 +01:00
|
|
|
url="http://marc.theaimsgroup.com/?l=gentoo-security&amp;m=106040714910563&amp;w=2">Here</ulink>
|
2007-08-03 00:09:56 +02:00
|
|
|
is a post describing configuring syslog-ng to work with Shorewall. Recent
|
2008-08-15 07:03:24 +02:00
|
|
|
<trademark>SUSE</trademark> releases come preconfigured with syslog-ng
|
2007-08-03 00:09:56 +02:00
|
|
|
with Netfilter messages (including Shorewall's) are written to
|
|
|
|
<filename>/var/log/firewall</filename>.</para>
|
2004-02-14 19:06:39 +01:00
|
|
|
</section>
|
|
|
|
|
2007-06-29 00:06:10 +02:00
|
|
|
<section id="Contents">
|
2004-02-14 19:06:39 +01:00
|
|
|
<title>Understanding the Contents of Shorewall Log Messages</title>
|
2012-05-24 22:54:59 +02:00
|
|
|
|
2004-02-14 19:06:39 +01:00
|
|
|
<para>For general information on the contents of Netfilter log messages,
|
2004-12-28 18:25:25 +01:00
|
|
|
see <ulink
|
2012-06-09 16:18:17 +02:00
|
|
|
url="http://logi.cc/en/2010/07/netfilter-log-format/">http://logi.cc/en/2010/07/netfilter-log-format/</ulink>.</para>
|
2012-05-24 22:54:59 +02:00
|
|
|
|
2004-12-28 18:25:25 +01:00
|
|
|
<para>For Shorewall-specific information, see <ulink
|
|
|
|
url="FAQ.htm#faq17">FAQ #17</ulink>.</para>
|
2004-02-14 19:06:39 +01:00
|
|
|
</section>
|
2008-07-07 22:42:54 +02:00
|
|
|
</article>
|