All of lore.kernel.org
 help / color / mirror / Atom feed
From: Pascal Italiaander <pc-secure@home.nl>
To: netfilter@lists.netfilter.org
Subject: Re: bootpc
Date: Thu, 5 Jun 2003 21:35:55 +0200	[thread overview]
Message-ID: <200306052135.55070.pc-secure@home.nl> (raw)
In-Reply-To: <3EDF2F41.8080505@ncl.ac.uk>

Op donderdag 5 juni 2003 13:53, schreef Matthew Pocock:
> Hi,
>
> I've set up my bridge+firewall, and everything is hunkeydory. I am doing
> statefull filtering. I let all traffic out, and all related/established
> traffic in. Then, I only allow new icmp & tcp:ssh connections in.
>
> To get windows 95 & 98 PCs on the inside to boot & join the network, I
> had to open up udp ports bootps & bootpc for new connections
> orriginating from the outside. I don't know the finer details about how
> these protocols work, but presumably they are connecting to the booting
> PC in response to some DHCP request it has made. Is there some module I
> should have loaded that would flag these connections as RELATED to some
> outgoing connection? Have I done something silly? Is this even possible?
>
> Thanks,
>
> Matthew

I'ts possible ,but a connection orriginating from the outside to boot internal 
your PC , no way. ??  Request for a DHCP should be orriginating from the 
inside. (your win95 +98). and reply should come from the outside.

No, you don't have to load a module.

but your very warm, there should be a rule to track these connections.
example:

DHCP_SERVER"211.124.45.2"

${IPTABLES} -A OUTPUT  -p udp -s 0/0 -d ${DHCP_SERVER} --sport 68 --dport 67 \ 
-m state --state NEW -j ACCEPT

${IPTABLES} -A INPUT  -p udp -s 0/0 -s ${DHCP_SERVER} --sport 67 --dport 68  \ 
-m state --state ESTABLISHED,RELATED -j ACCEPT

hmm.. silly NO , silly are the people who don't ask , but just do.

Pascal





  reply	other threads:[~2003-06-05 19:35 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2003-06-05 11:53 bootpc Matthew Pocock
2003-06-05 19:35 ` Pascal Italiaander [this message]
2003-06-06  9:26   ` bootpc Matthew Pocock
2003-06-06 10:20     ` bootpc Pascal Italiaander

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200306052135.55070.pc-secure@home.nl \
    --to=pc-secure@home.nl \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.