All of lore.kernel.org
 help / color / mirror / Atom feed
* OUTPUT ACCEPT, but can't see out
@ 2004-03-04  1:11 Kevin Mulcahy
  2004-03-04  1:23 ` Unknown, Alistair Tonner
       [not found] ` <200403032023.35644.Alistair Tonner <>
  0 siblings, 2 replies; 5+ messages in thread
From: Kevin Mulcahy @ 2004-03-04  1:11 UTC (permalink / raw)
  To: netfilter

Hi All
I have a very simple set of rules, with default policy for INPUT being 
DROP and  default OUTPUT being ACCEPT.
However, I can't hit anything on the outside.  I can't ping, ssh - nothing.
When I flush everything I can see outside no problem.
My script is:

IPTABLES="/sbin/iptables"
INTERFACE="eth0"
SERVER="x.x.x.x"
SSHA1="y.y.y.y"
$IPTABLES -P INPUT DROP
$IPTABLES -P OUTPUT ACCEPT
$IPTABLES -P FORWARD DROP
$IPTABLES -A INPUT -i $INTERFACE -p tcp -s $SSHA1 -d $SERVER --dport 22 
-j ACCEPT
$IPTABLES -A INPUT -i $INTERFACE -p tcp -s $ALLIP -d $ALLIP --dport 80 
-j ACCEPT
$IPTABLES -A INPUT -i $INTERFACE -p tcp -s $ALLIP -d $ALLIP --dport 443 
-j ACCEPT
$IPTABLES -A INPUT -i $INTERFACE -p ALL -m state --state 
ESTABLISHED,RELATED -j ACCEPT
#Note - this appears to generate an error
# iptables: No chain/target/match by that name
# but would that affect OUTPUT ???
$IPTABLES -A INPUT -i $INTERFACE -p ALL -j RETURN

$IPTABLES -A OUTPUT -o $INTERFACE -p ALL  -j ACCEPT


Cheers
Kev.


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2004-03-04 23:02 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-03-04  1:11 OUTPUT ACCEPT, but can't see out Kevin Mulcahy
2004-03-04  1:23 ` Unknown, Alistair Tonner
     [not found] ` <200403032023.35644.Alistair Tonner <>
2004-03-04  2:06   ` Kevin Mulcahy
2004-03-04 13:03     ` Unknown, Alistair Tonner
     [not found]     ` <200403040803.56158.Alistair Tonner <>
2004-03-04 23:02       ` Kevin Mulcahy

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.