All of lore.kernel.org
 help / color / mirror / Atom feed
* ipset issues
@ 2016-05-25 20:42 Art Emius
  2016-05-25 20:58 ` Jozsef Kadlecsik
  0 siblings, 1 reply; 6+ messages in thread
From: Art Emius @ 2016-05-25 20:42 UTC (permalink / raw)
  To: netfilter

Hello guys,

Recently I've encountered an issue with using ipset in my firewall.

I use Debian Linux 8.4, running in virtual machine inside ESXi 5.5.
My host is 192.168.1.2, remote host is 192.168.1.1.
I'm running ssh server on my host and want to limit access to it using
one rule with two sets of different types like this:

iptables -t filter -A INPUT -m set --match-set NETS_IFACE src,src -m
set --match-set SSH src,dst,dst -j ACCEPT
iptables -p OUTPUT ACCEPT

ipset create SSH hash:ip,port,ip hashsize 8 maxelem 8 family inet
ipset add SSH 192.168.1.1,tcp:22,192.168.1.2

ipset create NETS_IFACE hash:net,iface hashsize 128 maxelem 128 family inet
ipset add NETS_IFACE 192.168.1.0/24,eth1

It doesn't work this way. eth1 really exists and handle traffic.
But If I use rule like this it works fine.
iptables -t filter -A INPUT -i eth1 -m set --match-set SSH src,dst,dst -j ACCEPT

What am I doing wrong?

Regards,
Art

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2016-05-31 11:05 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-05-25 20:42 ipset issues Art Emius
2016-05-25 20:58 ` Jozsef Kadlecsik
2016-05-28 19:09   ` Art Emius
2016-05-30 19:19     ` Jozsef Kadlecsik
2016-05-31 10:25       ` Pablo Neira Ayuso
2016-05-31 11:05         ` Jozsef Kadlecsik

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.