[ale] Monitor Internet Traffic

Chris Fowler cfowler at outpostsentinel.com
Wed Aug 12 18:04:17 EDT 2015


ID-10-T error. I'm running 48 and not 42 on that subnet! Another thing is that src and dst seem to be reversed on the page. Below is what works. 

Chain INPUT (policy ACCEPT 600 packets, 57112 bytes) 
pkts bytes target prot opt in out source destination 
0 0 DROP udp -- eth0 * 0.0.0.0/0 0.0.0.0/0 udp dpt:53 
0 0 REJECT tcp -- eth0 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:53 reject-with tcp-reset 
7 734 ACCEPT all -- ap0 * 192.168.48.0/29 0.0.0.0/0 

Chain FORWARD (policy ACCEPT 222 packets, 112638 bytes) 
pkts bytes target prot opt in out source destination 
131 90380 TRAFFIC_ACCT_IN all -- ap0 * 0.0.0.0/0 0.0.0.0/0 
91 22258 TRAFFIC_ACCT_OUT all -- * ap0 0.0.0.0/0 0.0.0.0/0 

Chain OUTPUT (policy ACCEPT 478 packets, 204523 bytes) 
pkts bytes target prot opt in out source destination 
6 760 ACCEPT all -- * ap0 0.0.0.0/0 192.168.48.0/29 

Chain TRAFFIC_ACCT (0 references) 
pkts bytes target prot opt in out source destination 

Chain TRAFFIC_ACCT_IN (1 references) 
pkts bytes target prot opt in out source destination 
131 90380 all -- * * 192.168.48.2 0.0.0.0/0 
0 0 all -- * * 192.168.48.3 0.0.0.0/0 
0 0 all -- * * 192.168.48.4 0.0.0.0/0 
0 0 all -- * * 192.168.48.5 0.0.0.0/0 
0 0 all -- * * 192.168.48.6 0.0.0.0/0 

Chain TRAFFIC_ACCT_OUT (1 references) 
pkts bytes target prot opt in out source destination 
91 22258 all -- * * 0.0.0.0/0 192.168.48.2 
0 0 all -- * * 0.0.0.0/0 192.168.48.3 
0 0 all -- * * 0.0.0.0/0 192.168.48.4 
0 0 all -- * * 0.0.0.0/0 192.168.48.5 
0 0 all -- * * 0.0.0.0/0 192.168.48.6 
91 22258 tcp -- * * 0.0.0.0/0 0.0.0.0/0 
0 0 icmp -- * * 0.0.0.0/0 0.0.0.0/0 
0 0 udp -- * * 0.0.0.0/0 0.0.0.0/0 
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mail.ale.org/pipermail/ale/attachments/20150812/c3fecf53/attachment.html>


More information about the Ale mailing list