X-Git-Url: http://git.ipfire.org/?p=people%2Fpmueller%2Fipfire-2.x.git;a=blobdiff_plain;f=src%2Finitscripts%2Fsystem%2Ffirewall;fp=src%2Finitscripts%2Fsystem%2Ffirewall;h=ab3a0bbf9c9a6151b89686c2308dac5b8be11944;hp=b0890c71731b8c90747227b6cacc540c5485289e;hb=78b65ea7e39c89573b7bf60c5d55b925363de832;hpb=dcbdc8f587a34e2790ac1e9caa7e804063d61a33 diff --git a/src/initscripts/system/firewall b/src/initscripts/system/firewall index b0890c7173..ab3a0bbf9c 100644 --- a/src/initscripts/system/firewall +++ b/src/initscripts/system/firewall @@ -32,6 +32,10 @@ iptables_init() { iptables -P FORWARD DROP iptables -P OUTPUT ACCEPT + # Enable TRACE logging to syslog + modprobe nf_log_ipv4 + sysctl -q -w net.netfilter.nf_log.2=nf_log_ipv4 + # Empty LOG_DROP and LOG_REJECT chains iptables -N LOG_DROP iptables -A LOG_DROP -m limit --limit 10/second -j LOG