[ previous ] [ next ] [ threads ]
 From:  "Chris Buechler" <cbuechler at gmail dot com>
 Cc:  m0n0wall at lists dot m0n0 dot ch
 Subject:  Re: [m0n0wall] Log Firewall
 Date:  Fri, 6 Oct 2006 10:34:51 -0400
On 10/6/06, Andrei Antonelli <andrei at hcrp dot fmrp dot usp dot br> wrote:
> I was analysing the m0n0wall logs in Diagnostics ( Firewall States ),
> there show me all the destinations when someone access some address,
> everything is logged.
> I executed the exec.php in monowall, and cat /var/log/filter.log,however
> the address destinations doesn't appear like in the  monowall web
> browser ( Firewall States ).
> Someone knows where is this informations with the logs when someone
> visist some
> address ??

It doesn't unless you enable logging on the firewall rule that's
passing that traffic.  Your default LAN to any rule is probably what's
passing most of this traffic and it doesn't have logging enabled by
default because of the volume of traffic likely to hit that rule.  If
you enable logging on that rule, make sure you setup logging to a
remote syslog server or you'll probably lose information you want to
see because m0n0wall's logs rotate relatively quickly (they're stored
in RAM).