четверг, 12 февраля 2015 г.

Rsyslog

Rate-limit

Feb 13 10:32:17 gw207 rsyslogd-2177: imuxsock begins to drop messages from pid 2178 due to rate-limiting
Feb 13 10:32:19 gw207 rsyslogd-2177: imuxsock lost 108 messages from pid 2178 due to rate-limiting
Feb 13 10:32:43 gw207 rsyslogd-2177: imuxsock begins to drop messages from pid 2178 due to rate-limiting
Feb 13 10:32:47 gw207 rsyslogd-2177: imuxsock lost 24 messages from pid 2178 due to rate-limiting


$SystemLogRateLimitInterval [number] default 5
$SystemLogRateLimitBurst [number] default 200
This means in plain words, that rate limiting will take effect if more than 200 messages occur in 5 seconds.
http://www.rsyslog.com/tag/rate-limiting/


Centralizing the audit log

active = yes
 direction = out
 path = builtin_syslog
 type = builtin 
 args = LOG_INFO
 format = string

and on the receiving rsyslog server, I configure the following to collect all audit events into one file per day:

 # Log linux audit log on original format:
 $template HostAudit, "/var/log/audit/%$YEAR%/%$MONTH%/%$DAY%/audit.log"
 $template auditFormat, "%msg%\n"
 :programname,   isequal,        "audispd"       -?HostAudit;auditFormat
 :programname,   isequal,        "audispd"       ~

http://wiki.rsyslog.com/index.php/Centralizing_the_audit_log

вторник, 3 февраля 2015 г.

IPSEC Mikrotik(server) + WinXP(client)

Mikrotik  v 6.21 (server)


/ip ipsec proposal
set [ find default=yes ] enc-algorithms=3des auth-algorithms=sha1

/ip pool
add name=vpn_pool ranges=192.168.4.200-192.168.4.254

/interface l2tp-server server
set default-profile=profile_l2tp enabled=yes ipsec-secret=243211 use-ipsec=yes
(ipser peer  создается автоматический)

/ip address
add address=10.10.10.1/30 interface=ether4 network=10.10.10.0

/ip firewall filter
add chain=input dst-address=10.10.10.1 dst-port=500,1701 in-interface=ether4 \
    protocol=udp src-address=10.10.10.2
add chain=input dst-address=10.10.10.1 in-interface=ether4 protocol=ipsec-esp \
    src-address=10.10.10.2

WinXP(client)

https://kb.iweb.com/entries/22387228-Configuring-new-VPN-L2TP-IPSec-connections-on-Windows-XP



Ссылки

http://wiki.mikrotik.com/wiki/L2TP_%2B_IPSEC_between_Mikrotik_router_and_a_PC
http://wiki.mikrotik.com/wiki/MikroTik_RouterOS_and_Windows_XP_IPSec/L2TP
http://nixman.info/?p=2308