Table of Contents
Installation on the management machine
syslog
First you have to ensure syslog sends kernel messages to /var/log/fwlog/fwlog.FIFO
.
Second make sure syslog accepts messages from remote firewalls (in distributed installation).
For syslog this could be done like:
- add
kern.* |/var/log/fwlog/fwlog.FIFO
to/etc/syslogd.conf
- to be able to receive logs from other machines make sure syslogd is started with option -r (
/etc/sysconfig/syslog
on Red Hat) - restart syslogd
fwlogd
- unpack package to eg.
/opt/fwlogview
mkdir /var/log/fwlog
mkfifo /var/log/fwlog/fwlog.FIFO
- copy fwlogd/fwlogd.startscript to
/etc/init.d/fwlogd
- aktivate fwlogd for your runlevels (
chkconfig –level 2345 fwlogd
on RedHat) - start fwlogd (
/etc/init.d/fwlogd start
)
fwlogmgmd
- package should already unpacked in eg.
/opt/fwlogview
- copy fwlogd/fwlogmgmd.startscript to
/etc/init.d/fwlogmgmd
- activate fwlogmgmd for your runlevels (
chkconfig –level 2345 fwlogmgmd
on RedHat) - copy fwlogmgmd.conf to
/etc/fwlogview/fwlogmgmd.conf
- adjust parameter for allowed fwlogview clients in fwlogmgmd.conf (only 127.0.0.1 is allowed by default)
- start fwlogmgmd (
/etc/init.d/fwlogmgmd start
) - check installation with “telnet localhost port” which should welcome you to fwlogmgmd