From: Antony Stone <Antony@Soft-Solutions.co.uk>
To: netfilter@lists.netfilter.org
Subject: Re: script firewall
Date: Tue, 13 Apr 2004 23:02:20 +0100 [thread overview]
Message-ID: <200404132302.20098.Antony@Soft-Solutions.co.uk> (raw)
In-Reply-To: <20040413212810.35514.qmail@web40506.mail.yahoo.com>
On Tuesday 13 April 2004 10:28 pm, Luis GUSTAVO wrote:
> Hi,
>
> i´m looking for a script for my adsl conection.
Er, that's not a very helpful description, but anyway...
> i found this
>
> iptables -F
> iptables -P INPUT DROP
> iptables -P OUTPUT DROP
> iptables -P FORWARD DROP
> iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
> iptables -A OUTPUT -p tcp --dport 22 -j ACCEPT
> iptables -A OUTPUT -p udp --dport 53 -j ACCEPT
> iptables -A OUTPUT -p tcp --dport 53 -j ACCEPT
Hmmm. Looks like one of mine :)
> when i apllyed this rules, my machines clients, don´t know acces my
> machine.
I tell you what - you let us know what you'd like your firewall to do, and we
might be able to help you.
If you don't tell us what your network setup is, and what you want your
firewall to do for you, we might not be able to suggest the perfect ruleset
for your needs.
I *did* say when I posted the above ruleset that it allowed me to access
*from* the machine the rules were running on *to* other systems by SSH, and
blocked *all access in to my machine* (which is what I consider to be
secure).
Therefore that fact that after you've applied these rules to your machine,
your clients can't access the system, suggests that the ruleset is working
correctly.
Tell us what you'd like to be different (and preferably tell us what you've
tried yourself and had problems with) and we'll see what we can do to help.
Regards,
Antony
--
"640 kilobytes (of RAM) should be enough for anybody."
- Bill Gates
Please reply to the list;
please don't CC me.
next prev parent reply other threads:[~2004-04-13 22:02 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-04-13 21:28 script firewall Luis GUSTAVO
2004-04-13 22:02 ` Antony Stone [this message]
2004-04-13 23:23 ` script firewall -- munged to OT -- very OT Unknown, Alistair Tonner
[not found] ` <200404131923.23985.Alistair Tonner <>
2004-04-14 0:05 ` Antony Stone
2004-04-14 0:53 ` Unknown, Alistair Tonner
[not found] <20040414025241.57105.qmail@web40509.mail.yahoo.com>
2004-04-14 8:30 ` script firewall Antony Stone
-- strict thread matches above, loose matches on Subject: below --
2004-04-20 19:53 Luis GUSTAVO
2004-04-20 20:10 ` Antony Stone
2004-04-20 20:21 ` Luis GUSTAVO
2004-04-20 20:32 ` Antony Stone
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200404132302.20098.Antony@Soft-Solutions.co.uk \
--to=antony@soft-solutions.co.uk \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox