Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Antony Stone <Antony@Soft-Solutions.co.uk>
To: netfilter@lists.netfilter.org
Subject: Re: I have no idea why this doesn't work...
Date: Thu, 22 Apr 2004 20:23:24 +0100	[thread overview]
Message-ID: <200404222023.24672.Antony@Soft-Solutions.co.uk> (raw)
In-Reply-To: <6.0.0.22.0.20040422085041.03eb3ec0@mail.garisonpiatt.com>

On Thursday 22 April 2004 7:58 pm, Garison Piatt wrote:

> Aloha.

G'day.

> I'm Garison, a web designer in Hawaii.

Hi.

> Below is a pared-down combination of several example scripts which did
> something reasonably close to what I want.  When I run this, however, I lose
> FTP, and who-knows-what-else.

Your posted ruleset *is* very long, yes, and by your own admission you're not 
quite sure what you're doing, so I recommend that you start simple and build 
up, ensuring there are no problems at each stage, so that when a problem does 
crop up, you know it must be the small part you just changed, rather than 
"somewhere in this great long script I've got".

Also, if you want help from this list, you'll have to be a bit clearer about 
what you are trying to do - specifically, what you want to allow, and what 
you want to block, so that we can understand why you have certain things in 
your ruleset (for example, you have some pretty strange destination port 
numbers in there, and I can't begin to guess why).

I recommend the following:

1. Describe your network setup to us so that we know what clients & servers 
you have on what network segments.

2. Explain what traffic you want to allow and what traffic you want to block 
(and what you want to log).

3. If you feel able to do so, show us a very simple script which does most of 
what you need, but falls down somewhere, and ask for guidance with the bit 
which doesn't work.   If you don't feel able to do this, don't worry, just 
ask for guidance on how to do what you described in (2), given the sitiuation 
in (1).

It's actually far easier to say "this is how I would go about what you 
require" than it is to say "this is where I think there's an error in your 
existing script which I don't fully understand".

Hope this helps,

Antony.

-- 
The difference between theory and practice is that in theory there is no 
difference, whereas in practice there is.

                                                     Please reply to the list;
                                                           please don't CC me.



  reply	other threads:[~2004-04-22 19:23 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-04-22 18:58 I have no idea why this doesn't work Garison Piatt
2004-04-22 19:23 ` Antony Stone [this message]
2004-04-22 19:43   ` Antony Stone

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200404222023.24672.Antony@Soft-Solutions.co.uk \
    --to=antony@soft-solutions.co.uk \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox