Aegis Aegis 1.7.x

  • ATTENTION! As of November 1, 2020, you are not able to reply to threads 6 months after the thread is opened if there are more than 500 posts in the thread.
    Threads will not be locked, so posts may still be edited by their authors.
    Just start a new thread on the topic to post if you get an error message when trying to reply to a thread.

foo man

Occasional Visitor
Could you explain to me what that last command is showing? "grep -F aegis /var/log/log-message | tail"
 
Last edited:

HELLO_wORLD

Very Senior Member
Could you explain to me what that last command is showing? "grep -F aegis /var/log/log-message | tail"
Sure,
grep -F aegis /var/log/log-message searches for lines with the text “aegis” in the file /var/log/log-message, that is where the system logs events (in particular iptables log events).
tail is showing only the last 10 lines of the piped request (the grep… one).
 

HELLO_wORLD

Very Senior Member
Thanks. So its not showing anything nefarious going on, right?
No, it shows what should be in the aegis log, here:
Many connections attempt blocked by aegis from LAN device 192.168.1.129 to WAN 10.201.126.241 and 192.168.11.1
 

foo man

Occasional Visitor
Hey HELLO_wORLD, I apologize for not getting to this sooner, but had some family issues to contend with here. Anyways, attached is the text file of the output you asked for. Hopefully it is all there, if not let me know and I will run it again. Thanks for taking a look at it whenever you get a chance, appreciate your help as always!
 

Attachments

  • aegis-debug.txt
    6.4 KB · Views: 5

HELLO_wORLD

Very Senior Member
Hey HELLO_wORLD, I apologize for not getting to this sooner, but had some family issues to contend with here. Anyways, attached is the text file of the output you asked for. Hopefully it is all there, if not let me know and I will run it again. Thanks for taking a look at it whenever you get a chance, appreciate your help as always!
You got it right, thanks.
For some reason, the aegis log file is empty.

While aegis is up, do you have the file /tmp/aegis-logd.awk, and what is in it?
Also, do you see a fifo node /tmp/aegis-logd?

Code:
ls -lt /tmp/aegis*
cat /tmp/aegis-logd.awk
 

foo man

Occasional Visitor
I do have the cat /tmp/aegis-logd.awk, but for some reason I am having a hard time trying to post it here.
 
Last edited:

HELLO_wORLD

Very Senior Member
I do have the cat /tmp/aegis-logd.awk, but for some reason I am having a hard time trying to post it here.
The ls looks ok, BUT, the awk file size is 1558 for me, so could be the problem!
What if you do aegis down; rm /tmp/aegis-logd.awk; aegis up
 

HELLO_wORLD

Very Senior Member
Thank you!
Sorry, I am not very present/available lately.
So the file is ok, the 1 byte difference is only router’s name between yours and mine.

Anyone else experiencing the same issue as @foo man ? Particularly R9000 users? Or is he the only one?
 

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top