Как сказано на сайте, добавил. Подскажете что не так сделал?
Код: Выделить всё
# iptables -A INPUT -j LOG
# iptables -A FORWARD -j LOG
Код: Выделить всё
kern.info /var/lib/psad/psadfifo
Код: Выделить всё
psad --Status
[+] psadwatchd (pid: 12629) %CPU: 0.0 %MEM: 0.0
Running since: Thu Oct 29 12:40:13 2009
[+] psad (pid: 12627) %CPU: 0.0 %MEM: 1.8
Running since: Thu Oct 29 12:40:13 2009
Command line arguments: [none specified]
Alert email address(es): postmaster@mail.domain
[+] Version: psad v2.1.5
[+] Top 50 signature matches:
[NONE]
[+] Top 25 attackers:
[NONE]
[+] Top 20 scanned ports:
[NONE]
[+] iptables log prefix counters:
[NONE]
DShield stats:
total emails: 0
total packets: 0
Total packet counters: tcp: 0, udp: 0, icmp: 0
[+] IP Status Detail:
[NONE]
Total scan sources: 0
Total scan destinations: 0
[+] These results are available in: /var/log/psad/status.out
Логи пишет
Код: Выделить всё
Oct 29 12:37:25 router kernel: Inbound:IN=vlan9 OUT= MAC=00:0e:2e:65:c3:1b:00:15:17:11:bf:2c:08:00:45:00:00:28 SRC=83.27.144.25 DST=193.78.254.14 LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=37580 DF PROTO=TCP SPT=4362 DPT=22 WINDOW=65039 RES=0x00 ACK URGP=0
Oct 29 12:37:25 router kernel: Inbound:IN=vlan9 OUT= MAC=00:0e:2e:65:c3:1b:00:15:17:11:bf:2c:08:00:45:00:00:5c SRC=83.27.144.25 DST=193.78.254.14 LEN=92 TOS=0x00 PREC=0x00 TTL=121 ID=37581 DF PROTO=TCP SPT=4362 DPT=22 WINDOW=65039 RES=0x00 ACK PSH URGP=0
Oct 29 12:37:26 router kernel: Inbound:IN=vlan9 OUT= MAC=00:0e:2e:65:c3:1b:00:15:17:11:bf:2c:08:00:45:00:00:5c SRC=83.27.144.25 DST=193.78.254.14 LEN=92 TOS=0x00 PREC=0x00 TTL=121 ID=37582 DF PROTO=TCP SPT=4362 DPT=22 WINDOW=64987 RES=0x00 ACK PSH URGP=0
Oct 29 12:37:26 router kernel: Inbound:IN=vlan9 OUT= MAC=00:0e:2e:65:c3:1b:00:15:17:11:bf:2c:08:00:45:00:00:28 SRC=83.27.144.25 DST=193.78.254.14 LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=37583 DF PROTO=TCP SPT=4362 DPT=22 WINDOW=64903 RES=0x00 ACK URGP=0