Linux Netfilter discussions
 help / color / mirror / Atom feed
* newbie
@ 2004-03-26 19:52 IT Clown
  2004-03-26 20:05 ` newbie David Cannings
  0 siblings, 1 reply; 4+ messages in thread
From: IT Clown @ 2004-03-26 19:52 UTC (permalink / raw)
  To: netfilter

Hi all

I am new to iptanles i am just wondering i have the
following in my iptables file.

INPUT DROP [0.0]
OUTPUT DROP [0.0]
FORWARD DROP [0.0]

as i understand that will drop every comunications.

what rules will i need to apply to allow www,ftp,mirc
browsing?

I want to do that on another pc behind the firewall.

Regards
__________________________________________________________________________
http://www.webmail.co.za/dialup Webmail ISP - Cool Connection, Cool Price


^ permalink raw reply	[flat|nested] 4+ messages in thread
* Newbie
@ 2003-10-29 19:19 David C. Hart
  2003-10-29 19:43 ` Newbie Jörg Schütter
  0 siblings, 1 reply; 4+ messages in thread
From: David C. Hart @ 2003-10-29 19:19 UTC (permalink / raw)
  To: netfilter

[-- Attachment #1: Type: text/plain, Size: 1177 bytes --]

I'm a bit of a nitwit and could use some pointers from more experienced
hands.

We changed routers recently and with it the processes. The objectives
remain the same:
1. To protect the server (running Apache, Postfix and Vftp).
2. To provide DShield reporting.
3. To get reliable data so that, from time to time, we can contact ISPs
when things get out of hand.

The setup is simple and does not use the router's NAT. 

I am using only the NAT IPtable. HTTP, SMTP, FTP and Pop3 get port
forwarded. Anything that doesn't get port forwarded is presumed to be
intrusive and gets logged and dropped. So far so good.

Questions:

1. Does this approach make sense? 

2. I'm getting the LAN address in the logs rather than the intended
destination IP. Is there some way to preserve the original data?

3. Is anyone aware of a decent log analyzer that will also provide host
resolution?

4. I would rather use the FILTER table for the refused connections to
reject rather than drop. I'm sure that it's simple but I just don't get
it. This would depend upon the filter table rules following the NAT
table rules. Where is this order established?

Thanks.

[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2004-03-26 20:05 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-03-26 19:52 newbie IT Clown
2004-03-26 20:05 ` newbie David Cannings
  -- strict thread matches above, loose matches on Subject: below --
2003-10-29 19:19 Newbie David C. Hart
2003-10-29 19:43 ` Newbie Jörg Schütter

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox