How can I set up the ULOG target with iptables and MySQL












1















I'm running CentOS 6.6 32bit as a firewall box using iptables.



I want to be able to use the ULOG target to store dropped packets in a MySQL database for statistical analysis.



After much Googling I can't really see how this is achieved or if it's even possible. I tried seeing if my kernel will support it




grep ULOG /boot/config-2.6.32-504.el6.i686
CONFIG_IP_NF_TARGET_ULOG=m
CONFIG_BRIDGE_EBT_ULOG=m



Which I think is telling that there is support? But I have no idea how to set this up, and most guides on the internet are very outdated or do not work.



Can anyone point me in the right direction?










share|improve this question














bumped to the homepage by Community 3 mins ago


This question has answers that may be good or bad; the system has marked it active so that they can be reviewed.




















    1















    I'm running CentOS 6.6 32bit as a firewall box using iptables.



    I want to be able to use the ULOG target to store dropped packets in a MySQL database for statistical analysis.



    After much Googling I can't really see how this is achieved or if it's even possible. I tried seeing if my kernel will support it




    grep ULOG /boot/config-2.6.32-504.el6.i686
    CONFIG_IP_NF_TARGET_ULOG=m
    CONFIG_BRIDGE_EBT_ULOG=m



    Which I think is telling that there is support? But I have no idea how to set this up, and most guides on the internet are very outdated or do not work.



    Can anyone point me in the right direction?










    share|improve this question














    bumped to the homepage by Community 3 mins ago


    This question has answers that may be good or bad; the system has marked it active so that they can be reviewed.


















      1












      1








      1








      I'm running CentOS 6.6 32bit as a firewall box using iptables.



      I want to be able to use the ULOG target to store dropped packets in a MySQL database for statistical analysis.



      After much Googling I can't really see how this is achieved or if it's even possible. I tried seeing if my kernel will support it




      grep ULOG /boot/config-2.6.32-504.el6.i686
      CONFIG_IP_NF_TARGET_ULOG=m
      CONFIG_BRIDGE_EBT_ULOG=m



      Which I think is telling that there is support? But I have no idea how to set this up, and most guides on the internet are very outdated or do not work.



      Can anyone point me in the right direction?










      share|improve this question














      I'm running CentOS 6.6 32bit as a firewall box using iptables.



      I want to be able to use the ULOG target to store dropped packets in a MySQL database for statistical analysis.



      After much Googling I can't really see how this is achieved or if it's even possible. I tried seeing if my kernel will support it




      grep ULOG /boot/config-2.6.32-504.el6.i686
      CONFIG_IP_NF_TARGET_ULOG=m
      CONFIG_BRIDGE_EBT_ULOG=m



      Which I think is telling that there is support? But I have no idea how to set this up, and most guides on the internet are very outdated or do not work.



      Can anyone point me in the right direction?







      iptables firewall






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Feb 18 '15 at 15:24









      Aditya KAditya K

      789821




      789821





      bumped to the homepage by Community 3 mins ago


      This question has answers that may be good or bad; the system has marked it active so that they can be reviewed.







      bumped to the homepage by Community 3 mins ago


      This question has answers that may be good or bad; the system has marked it active so that they can be reviewed.
























          2 Answers
          2






          active

          oldest

          votes


















          0














          See here. You need a ulogd utility, available at least in Debian as the ulogd package; you can also install ulogd-mysql for logging into MySQL.






          share|improve this answer































            0














            Based on this answer, ULOG target is obsolete and it was replaced by target NFLOG. You should try an iptables rule like the following:



            IPTABLES -A OUTPUT -j NFLOG






            share|improve this answer























              Your Answer








              StackExchange.ready(function() {
              var channelOptions = {
              tags: "".split(" "),
              id: "106"
              };
              initTagRenderer("".split(" "), "".split(" "), channelOptions);

              StackExchange.using("externalEditor", function() {
              // Have to fire editor after snippets, if snippets enabled
              if (StackExchange.settings.snippets.snippetsEnabled) {
              StackExchange.using("snippets", function() {
              createEditor();
              });
              }
              else {
              createEditor();
              }
              });

              function createEditor() {
              StackExchange.prepareEditor({
              heartbeatType: 'answer',
              autoActivateHeartbeat: false,
              convertImagesToLinks: false,
              noModals: true,
              showLowRepImageUploadWarning: true,
              reputationToPostImages: null,
              bindNavPrevention: true,
              postfix: "",
              imageUploader: {
              brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
              contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
              allowUrls: true
              },
              onDemand: true,
              discardSelector: ".discard-answer"
              ,immediatelyShowMarkdownHelp:true
              });


              }
              });














              draft saved

              draft discarded


















              StackExchange.ready(
              function () {
              StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f185530%2fhow-can-i-set-up-the-ulog-target-with-iptables-and-mysql%23new-answer', 'question_page');
              }
              );

              Post as a guest















              Required, but never shown

























              2 Answers
              2






              active

              oldest

              votes








              2 Answers
              2






              active

              oldest

              votes









              active

              oldest

              votes






              active

              oldest

              votes









              0














              See here. You need a ulogd utility, available at least in Debian as the ulogd package; you can also install ulogd-mysql for logging into MySQL.






              share|improve this answer




























                0














                See here. You need a ulogd utility, available at least in Debian as the ulogd package; you can also install ulogd-mysql for logging into MySQL.






                share|improve this answer


























                  0












                  0








                  0







                  See here. You need a ulogd utility, available at least in Debian as the ulogd package; you can also install ulogd-mysql for logging into MySQL.






                  share|improve this answer













                  See here. You need a ulogd utility, available at least in Debian as the ulogd package; you can also install ulogd-mysql for logging into MySQL.







                  share|improve this answer












                  share|improve this answer



                  share|improve this answer










                  answered Feb 18 '15 at 15:45









                  wurtelwurtel

                  10.4k11526




                  10.4k11526

























                      0














                      Based on this answer, ULOG target is obsolete and it was replaced by target NFLOG. You should try an iptables rule like the following:



                      IPTABLES -A OUTPUT -j NFLOG






                      share|improve this answer




























                        0














                        Based on this answer, ULOG target is obsolete and it was replaced by target NFLOG. You should try an iptables rule like the following:



                        IPTABLES -A OUTPUT -j NFLOG






                        share|improve this answer


























                          0












                          0








                          0







                          Based on this answer, ULOG target is obsolete and it was replaced by target NFLOG. You should try an iptables rule like the following:



                          IPTABLES -A OUTPUT -j NFLOG






                          share|improve this answer













                          Based on this answer, ULOG target is obsolete and it was replaced by target NFLOG. You should try an iptables rule like the following:



                          IPTABLES -A OUTPUT -j NFLOG







                          share|improve this answer












                          share|improve this answer



                          share|improve this answer










                          answered Aug 23 '18 at 10:59









                          pagliucapagliuca

                          163116




                          163116






























                              draft saved

                              draft discarded




















































                              Thanks for contributing an answer to Unix & Linux Stack Exchange!


                              • Please be sure to answer the question. Provide details and share your research!

                              But avoid



                              • Asking for help, clarification, or responding to other answers.

                              • Making statements based on opinion; back them up with references or personal experience.


                              To learn more, see our tips on writing great answers.




                              draft saved


                              draft discarded














                              StackExchange.ready(
                              function () {
                              StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f185530%2fhow-can-i-set-up-the-ulog-target-with-iptables-and-mysql%23new-answer', 'question_page');
                              }
                              );

                              Post as a guest















                              Required, but never shown





















































                              Required, but never shown














                              Required, but never shown












                              Required, but never shown







                              Required, but never shown

































                              Required, but never shown














                              Required, but never shown












                              Required, but never shown







                              Required, but never shown







                              Popular posts from this blog

                              Histoire des bourses de valeurs

                              Why is there Russian traffic in my log files?

                              Rename multiple files to decrement number in file name?