|
|||
![]() Университет Беркли (слайдшоу) • Сайт у-та • файлы • форум |
|||
|
Школа
хинди
Войти Вы ещё не зарегистрировались? Сделайте это здесь: Новый пользователь События На середину августа 2008 г. как раз в лунное затмение был намечен (ну, не глупость же?!) запуск сверхмощного ускорителя в Швейцарии. Правда, потом был перенесен. Статьи apache bash Руководство FreeBSD Вопросы и ответы Пособие для новичков Beginners Guide Книги и статьи O'Reilly OnLamp chmod chown chroot chrootbind clamav commands curl cwhois defence deinstalling dns file_permissions FirewallWindowsServer2008 reebsdjail fw gate install ip lex mysqlcommands nvdriver packages permission permissions pf log php ports portsentry portsupgrade portupgrade proftpdwithmysql Qemu rndc rus rusFreeBSD screenfreebsd62 secure secure2 sitemap sound thank transl VHCSonFedoraCore3 vi xorg-upgrade |
Защита малой сети с помощью OpenBSD, Часть 4Pages: 1, 2
Which Packets Do You Want to Capture?
Why do some packets get written to /var/log/pflog and some do not? It all boils down to the way Packets are written to
Two special cases we have not discussed yet are the
to
To log all traffic on ExtIF, we'd need to add the
But if we are really concerned about security, shouldn't we be logging all packets arriving and leaving on all interfaces on the firewall? Ideally, yes, because that is the only way to ensure that you know what goes on over the boundary between your network and the rest of the world. But in such cases, you need to construct an efficient system for automated log analysis and management. Log files grow fast and take up a lot of storage space; it is essential that you gather only as much data as you can analyze. OK, suppose that you decide to log all traffic on all interfaces.
The first thing you need to do is turn global logging on by adding the
Rather than being a real time display, this command updates in short
intervals. If all goes well, you are now monitoring all traffic
passing, and attempting to pass, through the firewall. There is a lot
of data to munch through, and if you are to manage it, you need to
learn how to use
You can decide which packets are displayed by
Remember that you can safely experiment with filtering expressions, because they do not affect the contents of
You've go a lot of reading to do this time, so I'll leave you now to
learn a few things, and will return soon to tackle the problem of
managing Until next time. Jacek Artymiak started his adventure with computers in 1986 with Sinclair ZX Spectrum. He's been using various commercial and Open Source Unix systems since 1991. Today, Jacek runs devGuide.net, writes and teaches about Open Source software and security, and tries to make things happen. |
||
|
Индия
| История Индии |
Индийские языки | Индийские
литературы | Искусство | Веб-дизайн |Вед-хост |Белрент (квартира в Минске) По вопросам, связанным с этим веб-узлом, владельцем
и
авторским правам обращайтесь по адресу |
|||