选一台电脑安装kiwi syslog daemon
在路由器我是这样设置的:
info-center syslog
info-center loghost 0 192.168.0.21 514 local7 notifications filter FIREWALL
然后设置一条acl:
[Router]dis acl 105
Using normal packet-filtering access rules now.
105 deny tcp any any equal 445 logging (3988557 matches, 191450736 bytes -- rule 1)