William Unruh
2024-02-08 02:55:35 UTC
Shore wall is dumping its messages into dmesg, rather than say
/var/log/shorewall (which is empty) That rather fills dmesg with DROP
messages
[8024391.572953] Shorewall:sshd-fw:DROP:IN=eno1 OUT= MAC=4c:ed:fb:c2:2a:f3:a0:ab:1b:88:6e:58:08:00 SRC=185.196.8.151 DST=192.168.0.3 LEN=40 TOS=0x00 PREC=0xA0 TTL=250 ID=54321 PROTO=TCP SPT=40237 DPT=22 WINDOW=65535 RES=0x00 SYN URGP=0
What might I have misconfigured?
/etc/shorewall/shorewall.conf has
###############################################################################
# L O G G I N G
###############################################################################
BLACKLIST_LOG_LEVEL=info
INVALID_LOG_LEVEL=info
LOG_MARTIANS=Yes
LOG_VERBOSITY=2
#LOGALLNEW=yes
LOGFILE=/var/log/shorewall
LOGFORMAT="Shorewall:%s:%s:"
LOGTAGONLY=No
LOGLIMIT=
MACLIST_LOG_LEVEL=info
RELATED_LOG_LEVEL=
RPFILTER_LOG_LEVEL=info
SFILTER_LOG_LEVEL=info
SMURF_LOG_LEVEL=info
STARTUP_LOG=/var/log/shorewall-init.log
TCP_FLAGS_LOG_LEVEL=info
UNTRACKED_LOG_LEVEL=
/var/log/shorewall (which is empty) That rather fills dmesg with DROP
messages
[8024391.572953] Shorewall:sshd-fw:DROP:IN=eno1 OUT= MAC=4c:ed:fb:c2:2a:f3:a0:ab:1b:88:6e:58:08:00 SRC=185.196.8.151 DST=192.168.0.3 LEN=40 TOS=0x00 PREC=0xA0 TTL=250 ID=54321 PROTO=TCP SPT=40237 DPT=22 WINDOW=65535 RES=0x00 SYN URGP=0
What might I have misconfigured?
/etc/shorewall/shorewall.conf has
###############################################################################
# L O G G I N G
###############################################################################
BLACKLIST_LOG_LEVEL=info
INVALID_LOG_LEVEL=info
LOG_MARTIANS=Yes
LOG_VERBOSITY=2
#LOGALLNEW=yes
LOGFILE=/var/log/shorewall
LOGFORMAT="Shorewall:%s:%s:"
LOGTAGONLY=No
LOGLIMIT=
MACLIST_LOG_LEVEL=info
RELATED_LOG_LEVEL=
RPFILTER_LOG_LEVEL=info
SFILTER_LOG_LEVEL=info
SMURF_LOG_LEVEL=info
STARTUP_LOG=/var/log/shorewall-init.log
TCP_FLAGS_LOG_LEVEL=info
UNTRACKED_LOG_LEVEL=