From: "Laila Winblad Berntsen" <john@pepco.no>
To: Thiago Lima <thiagolima@webforce.com.br>, netfilter@lists.netfilter.org
Subject: Re: SNAT firewall maybe compromised. Misconfiguration?
Date: Tue, 29 Apr 2003 19:08:01 +0200 [thread overview]
Message-ID: <003001c30e71$e4213260$010a0a0a@suburban> (raw)
In-Reply-To: 004301c30e61$541d5190$1800a8c0@medusa
This is only telling whats the policy of the chain, setting it to DROP
will drop all packets that dont match a rule in the chain.
A good idea would be to put them first.
Regards
John Berntsen
----- Original Message -----
From: "Thiago Lima " <thiagolima@webforce.com.br>
To: <Alistair@nerdnet.ca>; <netfilter@lists.netfilter.org>
Sent: Tuesday, April 29, 2003 5:09 PM
Subject: RE: SNAT firewall maybe compromised. Misconfiguration?
>
> No, I did not.
>
> The script was cut off, but only in some portforwarding rules, just more
> 5 redirects.
>
> Should I use this -P INPUT DROP -P FORWARD DROP in both interfaces? In
> the end of my script?
>
> thanks
> thiago.
>
>
> -----Original Message-----
> From: Alistair Tonner [mailto:Alistair@nerdnet.ca]
> S
>
> You aren't showing us your policies, and that leads me to
> believe
> that the chain policies might be ACCEPT ... which is very not
> good.
> Also it ranter looks like this script was cut off.... so I can't
> be sure...
>
> $IPTABLES -P INPUT DROP
> $IPTABLES -P FORWARD DROP
>
> ?? do you do this at all??
> --
>
> Alistair Tonner
> nerdnet.ca
> Senior Systems Analyst - RSS
>
> Any sufficiently advanced technology will have the appearance of
> magic.
> Lets get magical!
>
>
prev parent reply other threads:[~2003-04-29 17:08 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-04-28 14:23 SNAT firewall maybe compromised. Misconfiguration? Thiago Lima
2003-04-29 14:55 ` Alistair Tonner
2003-04-29 15:09 ` Thiago Lima
2003-04-29 17:08 ` Laila Winblad Berntsen [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='003001c30e71$e4213260$010a0a0a@suburban' \
--to=john@pepco.no \
--cc=netfilter@lists.netfilter.org \
--cc=thiagolima@webforce.com.br \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.