Audit Logging

Proper auditing is even more important on the gateway than it is on the client machines. The gateway is the contact point with the outside world, and it will receive nonstop abuse from all over the Internet. Because of this, it’s vital to keep a good eye on the logs of this machine.

The services arpwatch, syslog, and swatch should all be installed and configured in the same fashion as described for the Linux client machines in Chapter 5.

Don’t forget to periodically log in to the gateway and check the logs and root user mail for evidence of a security breach. Even better, forward this information to an email account you check often.

Get 802.11 Security now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.