1. First, add a new chain with a reasonable name:
app
iptables -N LOGGINGide
2. Next, insert a rule at the appropriate point (hence me using --line-numbers
above). You could replace the existing REJECT
at line 5 in its entirety as its functionality will be moved into the LOGGING
chain (where I change it to a DROP
anyway):spa
iptables -I INPUT 5 -j LOGGINGdebug
3. Add the actual logging rule nextrest
iptables -A LOGGING -j LOG --log-prefix "DROP: " --log-level 7code
iptables -A LOGGING -j DROPblog
service iptables saveip
service iptables restart
get
4. vi /etc/rsyslog.confit
kern.debug /var/log/iptables.log
service rsyslog restart
5. vi /etc/logrotate.d/syslog
add /var/log/iptables.log to list of filenames