Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Andrew Beverley <andy@andybev.com>
To: Azerty Ytreza <007liamg007@gmail.com>
Cc: netfilter@vger.kernel.org
Subject: Re: Problem with log which are corrupted and need help with hitcount and FORWARD rules
Date: Sat, 22 Oct 2011 15:25:17 +0100	[thread overview]
Message-ID: <1319293517.26402.6312.camel@andybev-desktop> (raw)
In-Reply-To: <CACMGiwZ-4Q-xvVQOx3MM79U7YrwafcW+cMxsU932dRKfkM46GQ@mail.gmail.com>

On Sat, 2011-10-22 at 16:14 +0200, Azerty Ytreza wrote:
> "What exactly are you trying to achieve? If you're changing to a FORWARD
> rule then I assume that you are trying to adapt your rules in order to
> block connections destined for a remote server, rather than the local
> host?"
> 
> I want to limit the number of connections which passtrough the host.

Okay, in which case you do want FORWARD.

> Yes, I can block that on the remote server but I prefer on the local
> if it's possible.

Do you really mean "local" (in which case you want OUTPUT) or do you
just mean on your gateway/firewall server that all the traffic passes
through?

> 
> "Do you really mean UDP?"
> 
> No, it's an error sorry. I have copy/paste other rules and adapt rules
> but forget to change udp to tcp.

Okay, so it's working now?

> "You've got a mixture of INPUT and FORWARD. Is that what you want?
> Remember that packets will never transverse both the INPUT and FORWARD
> chains."
> 
> The port 443 is blocked by default it's for that which I open and
> after redirect. If I made only a FORWARD it's open directly the port
> without INPUT rules ?

It depends where you're blocking it. What's the default FORWARD rule?
ACCEPT?

The bottom line is that you need all your rules in FORWARD *or* INPUT. A
picture paints a thousand words:

http://jengelh.medozas.de/images/nf-packet-flow.png

Or for a simpler (out of date) version:

http://www.docum.org/docum.org/kptd/

> 
> 
> Thank you for your response !

No problem, but please put your responses in-line to the original email
rather than copying and pasting to the top! Oh, and copy the list as
well.

Andy



  parent reply	other threads:[~2011-10-22 14:25 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-10-22  8:43 Problem with log which are corrupted and need help with hitcount and FORWARD rules Azerty Ytreza
2011-10-22 13:20 ` Andrew Beverley
     [not found]   ` <CACMGiwZ-4Q-xvVQOx3MM79U7YrwafcW+cMxsU932dRKfkM46GQ@mail.gmail.com>
2011-10-22 14:25     ` Andrew Beverley [this message]
2011-10-22 15:11       ` Azerty Ytreza
2011-10-22 15:27         ` Andrew Beverley
2011-10-22 15:33           ` Azerty Ytreza
2011-10-22 16:01             ` Andrew Beverley
     [not found]               ` <CACMGiwbCxg8a19r-wErFyh-KWDX9tx42GvFo20Pq2zF_Sr9cKg@mail.gmail.com>
2011-10-23 13:51                 ` Andrew Beverley
     [not found]                 ` <1319377798.26402.6408.camel@andybev-desktop>
2011-10-23 21:04                   ` Azerty Ytreza

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1319293517.26402.6312.camel@andybev-desktop \
    --to=andy@andybev.com \
    --cc=007liamg007@gmail.com \
    --cc=netfilter@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox