From: "kenn murrah" <kenn@thebytebusiness.com>
To: netfilter@lists.netfilter.org
Subject: Re: newbie question about port blocking
Date: Thu, 17 Apr 2003 09:33:04 -0500 [thread overview]
Message-ID: <004701c304ee$4176fb30$2d64a8c0@murrahboy> (raw)
In-Reply-To: 200304171622.51239.kimj@dawn.dk
Thanks, Kim. I'll try that ...
BTW, i *AM* using squid, and my iptables already includes:
iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j
REDIRECT --to-port 3128
so, will the setup you describe be the only thing i need to add in order to
block non-http ports?
Thanks again,
Kenn
----- Original Message -----
From: "Kim Jensen" <kimj@dawn.dk>
To: "kenn murrah" <kenn@thebytebusiness.com>;
<netfilter@lists.netfilter.org>
Sent: Thursday, April 17, 2003 9:22 AM
Subject: Re: newbie question about port blocking
> Hi Kenn,
>
> A simple setup will be something like this:
>
> iptables -i lo -j ACCEPT
> iptables -p tcp --dport 80 -j ACCEPT
> iptables -j DROP
>
> If you are using a transparent proxy, ala Squid, you may have to add some
more
> rules.
>
> /Kim
>
> On Thursday 17 April 2003 15:49, kenn murrah wrote:
> > Sorry for the elementary nature of this question ... I've just installed
> > linux and have a transparent proxy working using iptables ... but my
goal
> > is to block ALL non-http traffic in both directions ... that is, i want
to
> > allow web access but no instant messenging, no ftp, etc.
> >
> > is there a simple line or two that i can add to iptables? please feel
free
> > to tell me to RTFM, but the tutorial i just downloaded is 151 pages, and
i
> > admit that i'm looking for a fast solution this morning ... (i'll study
the
> > manual on the way home tonight on the train -- i promise!)
> >
> > can anyone help me out? all advice MOST appreciated.
>
>
next prev parent reply other threads:[~2003-04-17 14:33 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2003-04-17 13:49 newbie question about port blocking kenn murrah
2003-04-17 14:22 ` Kim Jensen
2003-04-17 14:33 ` kenn murrah [this message]
2003-04-17 15:05 ` Cedric Blancher
2003-04-17 20:06 ` kenn murrah
2003-04-17 14:37 ` Kim Jensen
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='004701c304ee$4176fb30$2d64a8c0@murrahboy' \
--to=kenn@thebytebusiness.com \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.