I enjoy playing around with OpenWrt. To most, the following, probably won't interest, but it was fun putting together.
At this point the router is logging IPTables-Dropped ONLY "outside interface" to a 15 GigaByte USB stick. From there, I have a log file monitoring program that catalogs the Source IP, Protocol, and Destination Port. It will also churn out how many drops happen in a day, hour, or month etc.
Where this also has some value is everything from logread AKA "System Log" is going to the USB stick as well. So, if in the future, there's some kind of issue, I won't have to worry about the log rolling.
Last items yet to be completed
1. Auto mount the USB after a reboot
2. Script the command that redirects the output of logread to the USB and place in rc.local.
3. Script the commands needed to always log the table drops into rc.local.
After that, it's off to the next thing.
(Last edited by davidc502 on 30 Jul 2015, 05:08)