From mboxrd@z Thu Jan 1 00:00:00 1970 From: "Doug Yeager" Subject: denying local traffic Date: Tue, 11 Feb 2003 10:06:40 -0500 Sender: netfilter-admin@lists.netfilter.org Message-ID: <000101c2d1df$3166fb60$bb00a8c0@DOUG1> Reply-To: Mime-Version: 1.0 Content-Type: multipart/alternative; boundary="----=_NextPart_000_0002_01C2D1B5.4890F360" Return-path: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: To: netfilter@lists.netfilter.org This is a multi-part message in MIME format. ------=_NextPart_000_0002_01C2D1B5.4890F360 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit I'm using nocat as a wireless gateway w/ the hostap driver. This is Great because I should be able to use iptables firewall rules to Administer things. I've had some success w/ these rules as I'm new to iptables. What I can't figure out is how to block local traffic between clients on the LAN. Basically, I want them to be invisible to each other but be able to get to the internet through the gateway. Right now they can get to the internet but can see each other's shares and so forth. What should be the iptables commands for doing this. My lan is 192.168.19.0/255.255.255.0 Help would be great as I've attempted many things w/o success. Thx, doug ------=_NextPart_000_0002_01C2D1B5.4890F360 Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable

I'm using nocat as a wireless gateway w/ the = hostap driver. This is =

Great because I should be able to use iptables = firewall rules to

Administer things. I've had some success w/ these rules as I'm new to =

iptables.

 

What I can't figure out is how to block local traffic between clients =

on the LAN. Basically, I want them to be invisible to each other but =

be able to get to the internet through the = gateway.

Right now they can get to the internet but can see each other's = shares

and so forth.

 

What should be the iptables commands for doing = this.

 

My lan is 192.168.19.0/255.255.255.0

 

Help would be great as I've attempted many things w/o = success.

 

Thx,

doug

 

------=_NextPart_000_0002_01C2D1B5.4890F360--