[lug] iptables mystery, redhat/fedora flavor

Sean Reifschneider jafo at tummy.com
Tue Jan 2 19:05:53 MST 2007


On Tue, Jan 02, 2007 at 01:58:36AM +0000, D. Stimits wrote:
>that with port scanning. What I can't verify is if it is the blanket 
>deny all at the end, or the specific deny earlier on...indications are 

If you use "iptables -L INPUT -vn", it will display hit counts for the
rules, allowing you to determine which rule is getting hit.  There is also
the "TRACE" target in iptables, but I don't know how well that is
supported.

Sean
-- 
 Before you criticize someone, you should walk a mile in their shoes.  That
 way, when you criticize them, you're a mile away and you have their shoes.
Sean Reifschneider, Member of Technical Staff <jafo at tummy.com>
tummy.com, ltd. - Linux Consulting since 1995: Ask me about High Availability




More information about the LUG mailing list