Community discussions

MikroTik App
 
RabbitAtNet
just joined
Topic Author
Posts: 18
Joined: Fri Dec 11, 2009 12:16 am

Log firewall connections to syslog

Sat May 11, 2013 4:00 pm

Hi everyone,

since a customer of mine had some trouble with the police, I want to implement a log showing which client (IP address) has talked to which server. I thought of using syslog for that. But if I set up a simple rule Monitoring the uplink, every inbound and outbound packet gets logged. This is way to much data to store and analyze.

What I would like to get is the same Information shown under /ip Firewall Connections at the console or on the Connections tab of the IP Firewall in winbox. Is there a way to get it working?

Greetings from Germany,
Rabbit@Net
 
Cetalfio
Member Candidate
Member Candidate
Posts: 224
Joined: Sat Sep 20, 2008 6:19 pm
Location: Italy

Re: Log firewall connections to syslog

Wed May 15, 2013 11:14 pm

you have two ways the first install one proxy server or the best way could be install Calea server from Mt ciao cetalfio
 
Feklar
Forum Guru
Forum Guru
Posts: 1724
Joined: Tue Dec 01, 2009 11:46 pm

Re: Log firewall connections to syslog

Thu May 16, 2013 12:17 am

Your best option is going to be using netflows with a collector, it will log what local IP connected to what remote IP and when and how much data was transfered. It's called Traffic Flow in the MikroTik. The easiest collector to probably setup that is free will be ntop.

If they want an actual packet capture, then some form of mirroring or calea will need to be setup.

Who is online

Users browsing this forum: critter, maigonis, mfischer, mquan1984, Nullcaller, raimondsp and 87 guests