Run a system command when an IPTables rule is matched

Viewed 7040

:)

I'm wanting to be able to run a system command when an IPTable rule is hit, passing the IP address of the remote device to it.

I've had a look around but found nothing. I thought of grepping logs, but I'm expecting a lot of traffic..

Any help would be fantastic!

Thanks

(If it helps, Ubuntu Linux is my platform of choice)

3 Answers

it is actually easy. we have 2 way to do this. If you use tail log then iptables will not depend on log result.

  1. you can use NFQUEUE. Please read my article if you have time. https://medium.com/@farizmuradov/useful-notes-about-nfqueue-80a2c271db1a Same article I have added my linkedin page.

  2. you can write simple router in application level and send data from iptables to listen port. In programming level you can execute scripts and send data again some port. Then you can continue by iptables.

Related