Bonsoir,
Adopté, c'est simplement ce que je cherchais...
Pour ma compréhension,j'ai visité syslog pour comprendre l'enregistrement fait avec ceci :
Code:
# Toutes les autres connexions sont enregistrées dans syslog
#$IPTABLES -t filter -A OUTPUT -j LOG
$IPTABLES -t filter -A INPUT -j LOG --log-level=4
Mais a vrai dire je sais pas quoi chercher ... quelle type de ligne et comment les traduires ...
Mon iptables (58420=SSH) :
Code:
root@lagache:/home/irena# iptables -S
-P INPUT DROP
-P FORWARD DROP
-P OUTPUT ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -j LOG
-A INPUT -p icmp -j DROP
-A INPUT -p tcp -m tcp --dport 58400 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 58410 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 58420 -j ACCEPT
-A INPUT -j LOG
Code:
root@lagache:/home/irena# iptables -L
Chain INPUT (policy DROP)
target prot opt source destination
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
LOG icmp -- anywhere anywhere LOG level warning
DROP icmp -- anywhere anywhere
ACCEPT tcp -- anywhere anywhere tcp dpt:58400
ACCEPT tcp -- anywhere anywhere tcp dpt:58410
ACCEPT tcp -- anywhere anywhere tcp dpt:58420
LOG all -- anywhere anywhere LOG level warning
Chain FORWARD (policy DROP)
target prot opt source destination
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
Et enfin au redémarrage de mon pc, les dernières lignes se syslog :
Code:
May 12 18:47:26 lagache kernel: [ 27.002602] e1000e: eth0 NIC Link is Up 100 Mbps Full Duplex, Flow Control: Rx/Tx
May 12 18:47:26 lagache kernel: [ 27.002606] e1000e 0000:00:19.0: eth0: 10/100 speed: disabling TSO
May 12 18:47:26 lagache kernel: [ 27.004069] ADDRCONF(NETDEV_CHANGE): eth0: link becomes ready
May 12 18:47:27 lagache kernel: [ 27.262042] IN=eth0 OUT= MAC= SRC=192.168.1.10 DST=224.0.0.251 LEN=230 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=210
May 12 18:47:27 lagache kernel: [ 27.293154] IN=eth0 OUT= MAC= SRC=192.168.1.10 DST=224.0.0.251 LEN=142 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=122
May 12 18:47:27 lagache kernel: [ 27.512352] IN=eth0 OUT= MAC= SRC=192.168.1.10 DST=224.0.0.251 LEN=230 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=210
May 12 18:47:27 lagache kernel: [ 27.762552] IN=eth0 OUT= MAC= SRC=192.168.1.10 DST=224.0.0.251 LEN=230 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=210
May 12 18:47:27 lagache kernel: [ 27.962755] IN=eth0 OUT= MAC= SRC=192.168.1.10 DST=224.0.0.251 LEN=212 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=192
May 12 18:47:28 lagache kernel: [ 28.446942] IN=eth0 OUT= MAC= SRC=192.168.1.10 DST=224.0.0.251 LEN=142 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=122
May 12 18:47:28 lagache kernel: [ 28.946909] IN=eth0 OUT= MAC= SRC=192.168.1.10 DST=224.0.0.251 LEN=179 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=159
May 12 18:47:28 lagache kernel: [ 29.115485] IN=eth0 OUT= MAC= SRC=192.168.1.10 DST=224.0.0.251 LEN=212 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=192
May 12 18:47:29 lagache kernel: [ 29.196786] IN=eth0 OUT= MAC= SRC=192.168.1.10 DST=224.0.0.251 LEN=179 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=159
May 12 18:47:29 lagache kernel: [ 29.447216] IN=eth0 OUT= MAC= SRC=192.168.1.10 DST=224.0.0.251 LEN=179 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=159
May 12 18:47:29 lagache kernel: [ 29.647751] IN=eth0 OUT= MAC= SRC=192.168.1.10 DST=224.0.0.251 LEN=167 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=147
May 12 18:47:29 lagache freshclam[1907]: ClamAV update process started at Sat May 12 18:47:29 2012
May 12 18:47:29 lagache freshclam[1907]: main.cvd is up to date (version: 54, sigs: 1044387, f-level: 60, builder: sven)
May 12 18:47:29 lagache freshclam[1907]: daily.cld is up to date (version: 14915, sigs: 170977, f-level: 63, builder: guitar)
May 12 18:47:29 lagache freshclam[1907]: bytecode.cld is up to date (version: 176, sigs: 39, f-level: 63, builder: neo)
May 12 18:47:29 lagache kernel: [ 29.789523] IN=eth0 OUT= MAC= SRC=192.168.1.10 DST=224.0.0.251 LEN=167 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=147
May 12 18:47:29 lagache kernel: [ 29.992719] IN=eth0 OUT= MAC= SRC=192.168.1.10 DST=224.0.0.251 LEN=179 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=159
May 12 18:47:30 lagache kernel: [ 30.243063] IN=eth0 OUT= MAC= SRC=192.168.1.10 DST=224.0.0.251 LEN=179 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=159
May 12 18:47:30 lagache kernel: [ 30.493246] IN=eth0 OUT= MAC= SRC=192.168.1.10 DST=224.0.0.251 LEN=179 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=159
May 12 18:47:30 lagache kernel: [ 30.597430] IN=eth0 OUT= MAC= SRC=192.168.1.10 DST=224.0.0.251 LEN=199 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=179
May 12 18:47:30 lagache freshclam[1907]: --------------------------------------
May 12 18:47:30 lagache kernel: [ 30.693749] IN=eth0 OUT= MAC= SRC=192.168.1.10 DST=224.0.0.251 LEN=167 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=147
May 12 18:47:31 lagache kernel: [ 31.266480] IN=eth0 OUT= MAC= SRC=192.168.1.10 DST=224.0.0.251 LEN=240 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=220
May 12 18:47:31 lagache kernel: [ 31.845644] IN=eth0 OUT= MAC= SRC=192.168.1.10 DST=224.0.0.251 LEN=167 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=147
May 12 18:47:33 lagache kernel: [ 33.996964] IN=eth0 OUT= MAC= SRC=192.168.1.10 DST=224.0.0.251 LEN=167 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=147
May 12 18:48:23 lagache kernel: [ 83.768844] soffice.bin[2441]: segfault at 7fd4f94535b8 ip 00007fd50041161c sp 00007fff57a6e158 error 4 in libvcllx.so[7fd500194