Linux Iptables Firewall: Log IP or TCP Packet Header
Iptables provides the option to log both IP and TCP headers in a log file. This is useful to:
=> Detect Attacks
=> Analyze IP / TCP Headers
=> Troubleshoot Problems
=> Intrusion Detection
=> Iptables Log Analysis
=> Use 3rd party application such as PSAD (a tool to detect port scans and other suspicious traffic)
=> Use as education tool to understand TCP / IP header formats etc.
How do I turn on Logging IP Packet Header Options?
Add the following command to your iptables script beo:
iptables -A INPUT -j LOG --log-ip-options iptables -A INPUT -j DROP
How do I turn on Logging TCP Packet Header Options?
Add the following command to your iptables script:
iptables -A INPUT -j LOG --log-tcp-options iptables -A INPUT -j DROP
You may need to add additional filtering criteria such as source and destination ports/IP-address and other connection tracking features. To see IP / TCP header use tail -f or grep command:
# tail -f /var/log/messages
Recommended readings:
- TCP Protocol
- iptables man page
Want to stay up to date with the latest Linux tips, news and announcements? Subscribe to our free e-mail newsletter or RSS feed to get all updates.
You can Email this page to a friend.
You may also be interested in other helpful articles:
- Linux Iptables block all network traffic
- Iptables allow CIPE connection request
- Linux Iptables allow or open IMAP server port
- No Route to Host error and solution
- Linux Iptables allow LDAP server incoming client request
Leave a Reply
We encourage your comments, and suggestions. But please stay on topic, be polite, and avoid spam. Thank you very much for stopping by our site!
Tags: destination ports, fedora iptables log, header options, intrusion detection, ip header, Iptables, iptables firewall, iptables script, linux connection log, linux firewall, linux firewall log, linux iptables log, log messages, packet header, party application, port scans, suspicious traffic, tcp header



Recent Comments
Yesterday ~ 3 Comments
Yesterday ~ 1 Comment
Yesterday ~ 9 Comments
Yesterday ~ 13 Comments
Yesterday ~ 3 Comments