From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Thiago Lima " Subject: RE: SNAT firewall maybe compromised. Misconfiguration? Date: Tue, 29 Apr 2003 12:09:22 -0300 Sender: netfilter-admin@lists.netfilter.org Message-ID: <004301c30e61$541d5190$1800a8c0@medusa> References: <200304291055.21445.Alistair@nerdnet.ca> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <200304291055.21445.Alistair@nerdnet.ca> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii" To: Alistair@nerdnet.ca, netfilter@lists.netfilter.org No, I did not. The script was cut off, but only in some portforwarding rules, just more 5 redirects. Should I use this -P INPUT DROP -P FORWARD DROP in both interfaces? In the end of my script? thanks thiago. -----Original Message----- From: Alistair Tonner [mailto:Alistair@nerdnet.ca] S You aren't showing us your policies, and that leads me to believe that the chain policies might be ACCEPT ... which is very not good. Also it ranter looks like this script was cut off.... so I can't be sure... $IPTABLES -P INPUT DROP $IPTABLES -P FORWARD DROP ?? do you do this at all?? -- Alistair Tonner nerdnet.ca Senior Systems Analyst - RSS Any sufficiently advanced technology will have the appearance of magic. Lets get magical!