Iptables: how do I LOG what's not being ACCEPTED and limit what gets logged?
- by Kris
How do I log what's not being accepted by the following rule:
iptables -A OUTPUT -p icmp --icmp-type 3 -m -limit --limit 10/minute -j ACCEPT
And how do I limit what's being logged because I don't want to log 1000s of pings?
My first thought was:
iptables -A OUTPUT -p icmp --icmp-type 3 -m -limit --limit 50/day -j LOG
iptables -A OUTPUT -p icmp --icmp-type 3 -m -limit --limit 10/minute -j ACCEPT
But that doesn't seem right to me.
I think this limits the logging to 50/day but not necessarily what is not being accepted, or am I wrong?