From: Antony Stone <Antony@Soft-Solutions.co.uk>
To: netfilter@lists.netfilter.org
Subject: Re: I have no idea why this doesn't work...
Date: Thu, 22 Apr 2004 20:23:24 +0100 [thread overview]
Message-ID: <200404222023.24672.Antony@Soft-Solutions.co.uk> (raw)
In-Reply-To: <6.0.0.22.0.20040422085041.03eb3ec0@mail.garisonpiatt.com>
On Thursday 22 April 2004 7:58 pm, Garison Piatt wrote:
> Aloha.
G'day.
> I'm Garison, a web designer in Hawaii.
Hi.
> Below is a pared-down combination of several example scripts which did
> something reasonably close to what I want. When I run this, however, I lose
> FTP, and who-knows-what-else.
Your posted ruleset *is* very long, yes, and by your own admission you're not
quite sure what you're doing, so I recommend that you start simple and build
up, ensuring there are no problems at each stage, so that when a problem does
crop up, you know it must be the small part you just changed, rather than
"somewhere in this great long script I've got".
Also, if you want help from this list, you'll have to be a bit clearer about
what you are trying to do - specifically, what you want to allow, and what
you want to block, so that we can understand why you have certain things in
your ruleset (for example, you have some pretty strange destination port
numbers in there, and I can't begin to guess why).
I recommend the following:
1. Describe your network setup to us so that we know what clients & servers
you have on what network segments.
2. Explain what traffic you want to allow and what traffic you want to block
(and what you want to log).
3. If you feel able to do so, show us a very simple script which does most of
what you need, but falls down somewhere, and ask for guidance with the bit
which doesn't work. If you don't feel able to do this, don't worry, just
ask for guidance on how to do what you described in (2), given the sitiuation
in (1).
It's actually far easier to say "this is how I would go about what you
require" than it is to say "this is where I think there's an error in your
existing script which I don't fully understand".
Hope this helps,
Antony.
--
The difference between theory and practice is that in theory there is no
difference, whereas in practice there is.
Please reply to the list;
please don't CC me.
next prev parent reply other threads:[~2004-04-22 19:23 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-04-22 18:58 I have no idea why this doesn't work Garison Piatt
2004-04-22 19:23 ` Antony Stone [this message]
2004-04-22 19:43 ` Antony Stone
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200404222023.24672.Antony@Soft-Solutions.co.uk \
--to=antony@soft-solutions.co.uk \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox