
D-14 iptables man Pages
LX Series Configuration Guide
are included in the standard distribution.
LOG
Turn on kernel logging of matching packets. When this
option is set for a rule, the Linux kernel will print some
information on all matching packets (like most IP header
fields) via the kernel log (where it can be read with
dmesg or syslogd(8)).
--log-level level
Level of logging (numeric or see syslog.conf(5)).
--log-prefix prefix
Prefix log messages with the specified prefix; up
to 29 letters long, and useful for distinguishing
messages in the logs.
--log-tcp-sequence
Log TCP sequence numbers. This is a security risk
if the log is readable by users.
--log-tcp-options
Log options from the TCP packet header.
--log-ip-options
Log options from the IP packet header.
MARK
This is used to set the netfilter mark value associated
with the packet. It is only valid in the mangle table.
--set-mark mark
REJECT
This is used to send back an error packet in response to
the matched packet: otherwise it is equivalent to DROP.
This target is only valid in the INPUT, FORWARD and OUTPUT
chains, and user-defined chains which are only called from
those chains. Several options control the nature of the
Comentarios a estos manuales