Posted: Sat Nov 20, 2010 19:09 Post subject: iptables log entries truncated
I had been running "DD-WRT v24-sp2 (10/10/09) vpn" for a while on a wrt54gl v1.1. It was stable and worked well for me.
Recently I decided to log certain dropped packets from iptables to a remote syslogd host. I noticed that longer log messages were truncated to 256 characters. Checking the forums threads and wiki indicated that I should not have been running this build as was recommended by the router database. So I reflashed to Eko's "dd-wrt.v24-15230_NEWD_std-nokaid_nohotspot_nostor.bin" build, hoping that the log truncation would be fixed too. No luck.
Here are some examples. Certain IP addresses have been obfuscated.
Code:
Nov 20 13:06:33 wrt54gl kernel: DROP IN=vlan1 OUT= MAC=00:25:9c:28:69:be:00:24:c4:27:b6:e2:08:00:45:20:00:28 SRC=72.14.213.109 DST=71.234.xxx.xxx LEN=40 TOS=0x00 PREC=0x20 TTL=47 ID=57910 PROTO=TCP SPT=993 DPT=49865 SEQ=917032339 ACK=0 WINDOW=0 RES=0x00 RST UR
Nov 20 13:06:33 wrt54gl kernel: DROP IN=vlan1 OUT= MAC=00:25:9c:28:69:be:00:24:c4:27:b6:e2:08:00:45:20:00:28 SRC=72.14.213.109 DST=71.234.xxx.xxx LEN=40 TOS=0x00 PREC=0x20 TTL=47 ID=16451 PROTO=TCP SPT=993 DPT=49877 SEQ=2874908834 ACK=0 WINDOW=0 RES=0x00 RST U
I've searched this forum, the wiki and Google'd but have not found any other reports of this. I would appreciate any pointers.
The upgrade to the Eko build was done per the peacock thread. 30-30-30, upgrade-wait 5mins, 30-30-30, manually reconfigure settings. This build seems to be working well so far too.
Posted: Sat Mar 12, 2011 8:21 Post subject: Same here
I'm having the same problem and I also can confirm that it's not the syslog server truncating things because I have log entries from other sources that exceed the 256 character limit.
My DD-WRT firmware version is reported by the DD-WRT admin interface as:
So????? _________________ Asus RT16N + OTRW
Kingston 4GB USB-disk 128 MB swap + 1.4GB ext3 on /opt + 2 GB ext3 on /mnt
Copperjet 1616 modem in ZipB-config
Asterisk, pixelserv & Pound running on router
Another Asus RT16N as WDS-bridge
Posted: Wed Mar 16, 2011 19:54 Post subject: So, what?
So? (I'm not sure if you're trying to be smart or looking for an answer like we are)
So... is this by design? A Known bug? On the radar to be fixed soon?
I can appreciate that they probably had to "draw the line" somewhere on log length. But it would be nice if the "line" could be adjusted through the web interface or command line.
Posted: Wed Mar 16, 2011 20:12 Post subject: Re: So, what?
david.woodward wrote:
So? (I'm not sure if you're trying to be smart or looking for an answer like we are)
So... is this by design? A Known bug? On the radar to be fixed soon?
I can appreciate that they probably had to "draw the line" somewhere on log length. But it would be nice if the "line" could be adjusted through the web interface or command line.
It does the same on my full-blown linux box. You should look for a non DD-WRT specific answer _________________ Asus RT16N + OTRW
Kingston 4GB USB-disk 128 MB swap + 1.4GB ext3 on /opt + 2 GB ext3 on /mnt
Copperjet 1616 modem in ZipB-config
Asterisk, pixelserv & Pound running on router
Another Asus RT16N as WDS-bridge