* Filter out broadcast messages
@ 2004-01-07 21:44 Gabby James
2004-01-07 21:58 ` Antony Stone
` (2 more replies)
0 siblings, 3 replies; 5+ messages in thread
From: Gabby James @ 2004-01-07 21:44 UTC (permalink / raw)
To: netfilter
Hi,
I would like to filter out all broadcast messages. The packets could come
from 255.255.255.255 or multiple other addresses of the form 10.*.*.255.
What kind of syntax do I use to DROP these packets? The line below will
filter out packets from 255.255.255.255 but I'm not sure what syntax to use
to DROP the other adresses.
iptables -A INPUT -d 255.255.255.255 -p udp -j DROP
Regards,
GJ
_________________________________________________________________
Worried about inbox overload? Get MSN Extra Storage now!
http://join.msn.com/?PAGE=features/es
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: Filter out broadcast messages
2004-01-07 21:44 Filter out broadcast messages Gabby James
@ 2004-01-07 21:58 ` Antony Stone
2004-01-07 22:02 ` Eric Leblond
2004-01-07 22:05 ` Antony Stone
2 siblings, 0 replies; 5+ messages in thread
From: Antony Stone @ 2004-01-07 21:58 UTC (permalink / raw)
To: netfilter
On Wednesday 07 January 2004 9:44 pm, Gabby James wrote:
> Hi,
>
> I would like to filter out all broadcast messages. The packets could come
> from 255.255.255.255 or multiple other addresses of the form 10.*.*.255.
> What kind of syntax do I use to DROP these packets? The line below will
> filter out packets from 255.255.255.255 but I'm not sure what syntax to use
> to DROP the other adresses.
Should be quite simple really - all you need to know is how many ethernet
interfaces are on your firewall, and the broadcast address for each (unless
you've got more than one subnet bound to a single ethernet port, ugh).
Remember that broadcast packets do not get routed, therefore you only ned to
be concerned with subnets which are local to your firewall.
Unless you have an unusual setup, I'll bet that's no more than three.
It wouldn't be at all hard to script automatically, either. Start with
something like:
for a in `/sbin/ifconfig | grep Bcast | tr -s ':' ' ' | cut -d' ' -f6`
do
iptables -A INPUT -d $a -j DROP
done
Regards,
Antony.
--
Anyone that's normal doesn't really achieve much.
- Mark Blair, Australian rocket engineer
Please reply to the list;
please don't CC me.
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: Filter out broadcast messages
2004-01-07 21:44 Filter out broadcast messages Gabby James
2004-01-07 21:58 ` Antony Stone
@ 2004-01-07 22:02 ` Eric Leblond
2004-01-07 22:05 ` Antony Stone
2 siblings, 0 replies; 5+ messages in thread
From: Eric Leblond @ 2004-01-07 22:02 UTC (permalink / raw)
To: Gabby James; +Cc: netfilter
[-- Attachment #1: Type: text/plain, Size: 312 bytes --]
Le mer 07/01/2004 à 22:44, Gabby James a écrit :
> iptables -A INPUT -d 255.255.255.255 -p udp -j DROP
You can use the addrtype module to filter it :
http://www.netfilter.org/documentation/pomlist/pom-extra.html#addrtype
BR,
--
Eric Leblond
Nufw, Now User Filtering Works (http://www.nufw.org)
[-- Attachment #2: Ceci est une partie de message numériquement signée. --]
[-- Type: application/pgp-signature, Size: 189 bytes --]
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: Filter out broadcast messages
2004-01-07 21:44 Filter out broadcast messages Gabby James
2004-01-07 21:58 ` Antony Stone
2004-01-07 22:02 ` Eric Leblond
@ 2004-01-07 22:05 ` Antony Stone
2 siblings, 0 replies; 5+ messages in thread
From: Antony Stone @ 2004-01-07 22:05 UTC (permalink / raw)
To: netfilter
On Wednesday 07 January 2004 9:44 pm, Gabby James wrote:
> Hi,
>
> I would like to filter out all broadcast messages. The packets could come
> from 255.255.255.255 or multiple other addresses of the form 10.*.*.255.
> What kind of syntax do I use to DROP these packets? The line below will
> filter out packets from 255.255.255.255 but I'm not sure what syntax to use
> to DROP the other adresses.
Second idea:
If you mean what you say, and the other broadcasts fit the pattern 10.*.*.255,
you could always use the little-known but perfectly valid netmaslk
255.0.0.255 in a rule such as:
iptables -I INPUT -s 10.0.0.255/255.0.0.255 -j DROP
This will do exactly what you asked - match packets where the source IP's
first byte=10 and the last byte=255, with the middle two bytes being
anything, and drop them.
Antony.
--
Perfection in design is achieved not when there is nothing left to add, but
rather when there is nothing left to take away.
- Antoine de Saint-Exupery
Please reply to the list;
please don't CC me.
^ permalink raw reply [flat|nested] 5+ messages in thread
* Re: Filter out broadcast messages
@ 2004-01-08 14:20 Gabby James
0 siblings, 0 replies; 5+ messages in thread
From: Gabby James @ 2004-01-08 14:20 UTC (permalink / raw)
To: netfilter
Thanks Antony and Eric for the ideas. Each idea has solved my problem, so
it is just a matter of deciding which one to go with. Thanks again!
>From: Antony Stone <Antony@Soft-Solutions.co.uk>
>To: netfilter@lists.netfilter.org
>Subject: Re: Filter out broadcast messages
>Date: Wed, 7 Jan 2004 22:05:29 +0000
>
>On Wednesday 07 January 2004 9:44 pm, Gabby James wrote:
>
> > Hi,
> >
> > I would like to filter out all broadcast messages. The packets could
>come
> > from 255.255.255.255 or multiple other addresses of the form 10.*.*.255.
> > What kind of syntax do I use to DROP these packets? The line below will
> > filter out packets from 255.255.255.255 but I'm not sure what syntax to
>use
> > to DROP the other adresses.
>
>Second idea:
>
>If you mean what you say, and the other broadcasts fit the pattern
>10.*.*.255,
>you could always use the little-known but perfectly valid netmaslk
>255.0.0.255 in a rule such as:
>
>iptables -I INPUT -s 10.0.0.255/255.0.0.255 -j DROP
>
>This will do exactly what you asked - match packets where the source IP's
>first byte=10 and the last byte=255, with the middle two bytes being
>anything, and drop them.
>
>Antony.
>
>--
>Perfection in design is achieved not when there is nothing left to add, but
>rather when there is nothing left to take away.
>
> - Antoine de Saint-Exupery
>
> Please reply to the
>list;
> please don't CC
>me.
>
>
_________________________________________________________________
Working moms: Find helpful tips here on managing kids, home, work — and
yourself. http://special.msn.com/msnbc/workingmom.armx
^ permalink raw reply [flat|nested] 5+ messages in thread
end of thread, other threads:[~2004-01-08 14:20 UTC | newest]
Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-01-07 21:44 Filter out broadcast messages Gabby James
2004-01-07 21:58 ` Antony Stone
2004-01-07 22:02 ` Eric Leblond
2004-01-07 22:05 ` Antony Stone
-- strict thread matches above, loose matches on Subject: below --
2004-01-08 14:20 Gabby James
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.