From: Jason Opperisano <opie@817west.com>
To: netfilter@lists.netfilter.org
Subject: Re: Reject all the interfaces
Date: Tue, 21 Dec 2004 23:05:41 -0500 [thread overview]
Message-ID: <1103688341.7337.26.camel@hubcap.ljm.dom> (raw)
In-Reply-To: <1103685827.9049.23.camel@che>
On Tue, 2004-12-21 at 22:23, Erico Augusto wrote:
> Hi,
>
> I had the simple task to block the connection of 3 workstation(loopback
> and eth0) after a certain hour. So, I decided to put the single rule:
>
> iptables -I OUTPUT -j REJECT --reject-with icmp-host-prohibited
>
> After that, a friend of mine told me the following:
>
> It's better to reject the eth0 only, because, with the rule above, I'm
> blocking the loopback also, and the services that depends on that
> "interface",
remove the quotes--lo is a real interface just like eth0. i agree with
your friend that blocking all packets on lo is a very bad idea if these
are workstations. since unix windowing environments are network
client/server architecture, blocking packets on lo has interesting side
effects like not being able to use your keyboard anymore (yes--i did
this once). also--if you're trying to block outbound network
connections, blocking lo isn't helping you achieve this result.
> such as all the unix sockets based applications.
unix domain sockets have nothing to do with the loopback interface.
> That is my doubt. I read a lot of documentation about the netfilter
> architecture, but there is that gap of knowledge. The documentation
> never speaks about the differences between unix and tcp sockets.
because netfilter doesn't deal with unix domain sockets. the netfilter
documentation never speaks about IPX/SPX or AppleTalk either, but i
don't consider that to be a short-coming.
> Instead of search directly in google,I decided to ask here in netfilter
> list: Where can I find that kind of information(nefilter x unix/tcp
> sockets)?
by searching google. or reading stevens' vol. 3
-j
--
"Me fail English? That's unpossible."
--The Simpsons
prev parent reply other threads:[~2004-12-22 4:05 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-12-22 3:23 Reject all the interfaces Erico Augusto
2004-12-22 4:05 ` Jason Opperisano [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=1103688341.7337.26.camel@hubcap.ljm.dom \
--to=opie@817west.com \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.