Re: Monitoring utility

Ruth Ivimey-Cook <[email protected]> Tue, 14 Oct 2025 00:54:37 +0100
Newsgroups gmane.comp.security.shorewall
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============2994429237497203058==
Content-Type: multipart/alternative;
 boundary="------------s6wlFXn3wM0kYMxZe00x46t9"
Content-Language: en-GB

This is a multi-part message in MIME format.
--------------s6wlFXn3wM0kYMxZe00x46t9
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

Luca,

The Wikipedia entry may be referring to the command 'shorewall 
logwatch', which shows (as they happen) messages which shorewall has 
added to the linux kernel filter rules.

Or possibly to 'shorewall show', which you can use to print out various 
facts about the shorewall configuration.

Shorewall is only involved in creating the firewall - the linux kernel 
is the thing that makes it happen. So you can use any tool you wish to 
monitor the linux kernel messages, such as journalctl, dmesg, syslog and 
probably more.

Of course _interpreting_ the messages you see is another story, and not 
an easy one.  I personally like shorewall because you have a sufficient 
degree of control but the config you create is moderated with "wisdom" 
from the creators. That doesn't mean it is simple.

Basic messages will be to inform you that a packet has been dropped or 
rejected. Dropped packets are just silently thrown away, while rejection 
involves sending a packet back to the sender telling them it was 
rejected. Neither packet gets to its destination.

Using the Macro facility is a bit of faff to start with but makes the 
rules file _a lot_ more comprehensible, so I suggest it is used. I 
haven't found a good list of existing macros (not saying it's not 
there!) but they're all under /usr/share/lib/shorewall, IIRC.

Get to know the tools tcpdump (which is simple) and tshark (which is 
complex but rewards with a lot more in return) for inspecting the 
traffic on the various interfaces of the computer. You can (perhaps even 
should) use multiple terminal windows to view different network 
interfaces simultaneously, which will give you a better idea of how 
things are changed. tshark is the command line version of wireshark, and 
is simpler and faster to use for this purpose.

If you are using VLANs, NAT or Masquerade things get a lot more complex 
because the packet addresses are being munged. I heartily recommend a 
good book on TCP/IP before delving into debugging these issues. I am 
still of the opinion that "Richard W. Stevens" book "TCP/IP Illustrated 
Volume 1" (and Vol 2) are the best, but other people may differ.

Hope this helps,

Ruth



On 10/10/2025 09:43, Luca Saccarola wrote:
> Hi there,
>
> Wikipedia (https://en.wikipedia.org/wiki/Shorewall) states that "A 
> monitoring utility packaged with Shorewall can be used to watch the 
> status of the system as it operates and to assist in testing.". Can 
> you tell me which utility they are referring to ?
>
> Best,
> Luca
>
>
> _______________________________________________
> Shorewall-users mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/shorewall-users
--------------s6wlFXn3wM0kYMxZe00x46t9
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<!DOCTYPE html>
<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    <p>Luca,</p>
    <p>The Wikipedia entry may be referring to the command 'shorewall
      logwatch', which shows (as they happen) messages which shorewall
      has added to the linux kernel filter rules.</p>
    <p>Or possibly to 'shorewall show', which you can use to print out
      various facts about the shorewall configuration.</p>
    <p>Shorewall is only involved in creating the firewall - the linux
      kernel is the thing that makes it happen. So you can use any tool
      you wish to monitor the linux kernel messages, such as journalctl,
      dmesg, syslog and probably more.</p>
    <p>Of course _interpreting_ the messages you see is another story,
      and not an easy one.  I personally like shorewall because you have
      a sufficient degree of control but the config you create is
      moderated with "wisdom" from the creators. That doesn't mean it is
      simple.</p>
    <p>Basic messages will be to inform you that a packet has been
      dropped or rejected. Dropped packets are just silently thrown
      away, while rejection involves sending a packet back to the sender
      telling them it was rejected. Neither packet gets to its
      destination.</p>
    <p>Using the Macro facility is a bit of faff to start with but makes
      the rules file _a lot_ more comprehensible, so I suggest it is
      used. I haven't found a good list of existing macros (not saying
      it's not there!) but they're all under /usr/share/lib/shorewall,
      IIRC. </p>
    <p>Get to know the tools tcpdump (which is simple) and tshark (which
      is complex but rewards with a lot more in return) for inspecting
      the traffic on the various interfaces of the computer. You can
      (perhaps even should) use multiple terminal windows to view
      different network interfaces simultaneously, which will give you a
      better idea of how things are changed. tshark is the command line
      version of wireshark, and is simpler and faster to use for this
      purpose.</p>
    <p>If you are using VLANs, NAT or Masquerade things get a lot more
      complex because the packet addresses are being munged. I heartily
      recommend a good book on TCP/IP before delving into debugging
      these issues. I am still of the opinion that "Richard W. Stevens"
      book "TCP/IP Illustrated Volume 1" (and Vol 2) are the best, but
      other people may differ.</p>
    <p>Hope this helps,</p>
    <p>Ruth</p>
    <p> </p>
    <p><br>
    </p>
    <p><br>
    </p>
    <div class="moz-cite-prefix">On 10/10/2025 09:43, Luca Saccarola
      wrote:<br>
    </div>
    <blockquote type="cite"
cite="mid:CAND9tcOVrTt=4bgOYmx8Antz8pCtAWH7kn-utACdsFr01+o+Nw@mail.gmail.com">
      <meta http-equiv="content-type" content="text/html; charset=UTF-8">
      <div dir="ltr">
        <div>
          <div style="font-family:verdana,sans-serif"
            class="gmail_default"><font size="2">Hi there,</font></div>
          <div class="gmail_default"><font size="2"><span
                style="font-family:verdana,sans-serif"><br>
              </span></font></div>
          <div style="font-family:verdana,sans-serif"
            class="gmail_default"><font size="2">Wikipedia (</font><a
              href="https://en.wikipedia.org/wiki/Shorewall"
              moz-do-not-send="true" class="moz-txt-link-freetext">https://en.wikipedia.org/wiki/Shorewall</a>) <font
              size="2">states that "<span
style="color:rgb(32,33,34);font-style:normal;font-variant-caps:normal;font-weight:400;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px;background-color:rgb(255,255,255);text-decoration:none;display:inline;float:none">A
                monitoring utility packaged with Shorewall can be used
                to watch the status of the system as it operates and to
                assist in testing.". C</span></font>an you tell me which
            utility they are referring to ?</div>
          <br>
        </div>
        <div>
          <div style="font-family:verdana,sans-serif;font-size:small"
            class="gmail_default">Best,</div>
        </div>
        <div>
          <div dir="ltr" class="gmail_signature"
            data-smartmail="gmail_signature">
            <div dir="ltr">
              <div>Luca</div>
            </div>
          </div>
        </div>
      </div>
      <br>
      <fieldset class="moz-mime-attachment-header"></fieldset>
      <br>
      <fieldset class="moz-mime-attachment-header"></fieldset>
      <pre wrap="" class="moz-quote-pre">_______________________________________________
Shorewall-users mailing list
<a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
<a class="moz-txt-link-freetext" href="https://lists.sourceforge.net/lists/listinfo/shorewall-users">https://lists.sourceforge.net/lists/listinfo/shorewall-users</a>
</pre>
    </blockquote>
  </body>
</html>

--------------s6wlFXn3wM0kYMxZe00x46t9--


--===============2994429237497203058==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============2994429237497203058==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline