On 23.01.2015 17:46, Tom Easte p wrote: > On 1/23/2015 5:29 AM, Gerhard Wiesinger wrote: >> Hello, >> >> I'm having a problem that I get doubled logs: >> Jan 23 14:22:05 fw kernel: [63639.395178] SW:net2fw: .... >> Jan 23 14:22:05 fw kernel: SW:net2fw: ... >> >> I read already FAQ and logging of shorewall and debugged rsyslog. >> >> It looks like that 2 messages are generated: >> 1.) via kernel logging (=> ends via $ModLoad imklog also in rsyslog) >> 2.) via syslog >> >> I know I can filter in rsyslog one of the messages. But I want to avoid >> the generation of the 2 messages. >> >> And: ULOG is due to IPv6 not an option > You can use NFLOG though...
It is already active as far as I see. cat /proc/net/netfilter/nf_log|grep -v NONE 2 nf_log_ipv4 (nf_log_ipv4) Is it possible to configure nf_log somewhere? From the docs: http://shorewall.net/shorewall_logging.html By default, Shorewall directs Netfilter to log using syslog. Where is that activated? And the kernel logs via kernel log too. Thnx. Ciao, Gerhard ------------------------------------------------------------------------------ New Year. New Location. New Benefits. New Data Center in Ashburn, VA. GigeNET is offering a free month of service with a new server in Ashburn. Choose from 2 high performing configs, both with 100TB of bandwidth. Higher redundancy.Lower latency.Increased capacity.Completely compliant. http://p.sf.net/sfu/gigenet _______________________________________________ Shorewall-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/shorewall-users
