Linux Netfilter discussions
 help / color / mirror / Atom feed
* can someone check this simple firewall?
@ 2003-08-14 18:28 Payal Rathod
  2003-08-13 18:58 ` Gavin Hamill
                   ` (2 more replies)
  0 siblings, 3 replies; 6+ messages in thread
From: Payal Rathod @ 2003-08-14 18:28 UTC (permalink / raw)
  To: netfilter

Hi,
I have designed a simple firewall ruleset. Can someone please check
them? 
It is kept at http://payal.staticky.com/firewall-1.txt

[Thanks Ralf, I will reply to your mail a bit later when someone
cross-checks this too.]

The objective is as follows,

		eth0=1.2.3.4	
  +----------+      +----------+        +--------------+
  | INTERNET +------+ LINUX    +--------+ WINDOWS      |
  |          |      | FIREWALL |        |   CLIENTS    |
  +----------+      +----------+        +--------------+
		 eth1=192.168.10.100	192.168.10.0/25

Linux box is connected to net thru a permanent ip (1.2.3.4)

LAN users can go anywhere on net as well as Linux box.
So can the Linux box.
But from outside people can connect only to port 21, 22, 80 and can ping
the Linux box (to check whether it is alive or not). Rest everything is
blocked.

Can someone please check my ruleset and tell me whether it will achieve
my obective. I can test that box for very less time so have to do all
the work from a different machine and then copy that file to that Linux
box. Hence any help in finding problems will be appreciated.

Thanks and bye.
With warm regards,
-Payal

-- 
"Visit GNU/Linux Success Stories"
http://payal.staticky.com
Guest-Book Section Updated.


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2003-08-14 18:28 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-08-14 18:28 can someone check this simple firewall? Payal Rathod
2003-08-13 18:58 ` Gavin Hamill
2003-08-14  5:27 ` Matching misc TCP header fields Elver Loho
2003-08-14  7:08   ` Maciej Soltysiak
2003-08-14 10:18 ` can someone check this simple firewall? Ralf Spenneberg
2003-08-14 11:01   ` Chris Wilson

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox