[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-users] logcheck, ipchains & portsentry



Hey all,

I installed logcheck, ipchains, & portsentry on all of my raq 3i's and
things are working o.k.  Rather slick actually and very functional.

I am at the stage now of trying to use the firewall features of ipchains.  I
have read quite a bit on it including the list archives and was hoping
someone with experience using it on the raq's might be willing to share
their script.  I am concerned about blocking/not blocking appropriate ports
particular to the raq's (port 81, etc...) and common software we all seem to
run.

In terms of portsentry and logcheck I would also appreciate it if anyone
would be wiling to share any of the config files.  I am going through to try
and exclude all the "raq" behavior but am not familiar enough with what is
normal vs. something that is important.  I would like to have the logs
parsed only for meaningful info and alerted accordingly.

TIA

Mike