Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Antony Stone <Antony@Soft-Solutions.co.uk>
To: netfilter@lists.netfilter.org
Subject: Re: script firewall
Date: Tue, 13 Apr 2004 23:02:20 +0100	[thread overview]
Message-ID: <200404132302.20098.Antony@Soft-Solutions.co.uk> (raw)
In-Reply-To: <20040413212810.35514.qmail@web40506.mail.yahoo.com>

On Tuesday 13 April 2004 10:28 pm, Luis GUSTAVO wrote:

> Hi,
>
> i´m looking for a script for my adsl conection.

Er, that's not a very helpful description, but anyway...

> i found this
>
> iptables -F
> iptables -P INPUT DROP
> iptables -P OUTPUT DROP
> iptables -P FORWARD DROP
> iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
> iptables -A OUTPUT -p tcp --dport 22 -j ACCEPT
> iptables -A OUTPUT -p udp --dport 53 -j ACCEPT
> iptables -A OUTPUT -p tcp --dport 53 -j ACCEPT

Hmmm.   Looks like one of mine :)

> when i apllyed this rules, my machines clients, don´t know acces my
> machine.

I tell you what - you let us know what you'd like your firewall to do, and we 
might be able to help you.

If you don't tell us what your network setup is, and what you want your 
firewall to do for you, we might not be able to suggest the perfect ruleset 
for your needs.

I *did* say when I posted the above ruleset that it allowed me to access 
*from* the machine the rules were running on *to* other systems by SSH, and 
blocked *all access in to my machine*  (which is what I consider to be 
secure).

Therefore that fact that after you've applied these rules to your machine, 
your clients can't access the system, suggests that the ruleset is working 
correctly.

Tell us what you'd like to be different (and preferably tell us what you've 
tried yourself and had problems with) and we'll see what we can do to help.

Regards,

Antony

-- 
"640 kilobytes (of RAM) should be enough for anybody."

 - Bill Gates

                                                     Please reply to the list;
                                                           please don't CC me.



  reply	other threads:[~2004-04-13 22:02 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-04-13 21:28 script firewall Luis GUSTAVO
2004-04-13 22:02 ` Antony Stone [this message]
2004-04-13 23:23   ` script firewall -- munged to OT -- very OT Unknown, Alistair Tonner
     [not found]   ` <200404131923.23985.Alistair Tonner <>
2004-04-14  0:05     ` Antony Stone
2004-04-14  0:53       ` Unknown, Alistair Tonner
     [not found] <20040414025241.57105.qmail@web40509.mail.yahoo.com>
2004-04-14  8:30 ` script firewall Antony Stone
  -- strict thread matches above, loose matches on Subject: below --
2004-04-20 19:53 Luis GUSTAVO
2004-04-20 20:10 ` Antony Stone
2004-04-20 20:21   ` Luis GUSTAVO
2004-04-20 20:32     ` Antony Stone

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200404132302.20098.Antony@Soft-Solutions.co.uk \
    --to=antony@soft-solutions.co.uk \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox