Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Michael Sconzo <msconzo@net.tamu.edu>
To: netfilter@lists.netfilter.org
Subject: Odd question with source based blocking
Date: Thu, 26 Aug 2004 16:57:03 -0500	[thread overview]
Message-ID: <20040826165702.H1111@net.tamu.edu> (raw)
In-Reply-To: <1093555992.4293.37.camel@porky>; from eric@inl.fr on Thu, Aug 26, 2004 at 11:33:12PM +0200

I have a brief (hopefully) question.

I currently have a box that sits inline with a firewall setup similiar
to the following

FORWARD - Policy - DROP
 * allow DNS
 * allow DHCP
 * all WEB
 * allow all from 192.168.1.0/24 -> BLOCKED
 * allow all to 192.168.1.0/24 -> BLOCKED

BLOCKED
 * Block this IP
 * Block this other IP
 * etc ...

I've tried setting the default policy of BLOCKED to accept, however it
doesn't seem to let traffic through that doesn't match any one of the
'block this IP rule'.

The only catch is, I remove the 'block this IP' rules from the BLOCKED
list, so it makes it hard to ensure an ALLOW rule remains at the
bottom.  Any ideas on how I can do this (default allow traffic not
hitting a rule on BLOCKED to be ALLOWED?

Thanks!
-=Mike

-- 
_
_ Michael J. Sconzo
_ Computing & Information Services, Texas A&M University

The New Testament offers the basis for modern computer coding theory,
in the form of an affirmation of the binary number system.
        But let your communication be Yea, yea; nay, nay: for
        whatsoever is more than these cometh of evil.
                -- Matthew 5:37


  reply	other threads:[~2004-08-26 21:57 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-08-26 21:26 Change of ip addresses continues.... :( Jason Opperisano
2004-08-26 21:33 ` Eric Leblond
2004-08-26 21:57   ` Michael Sconzo [this message]
  -- strict thread matches above, loose matches on Subject: below --
2004-08-26 22:49 Odd question with source based blocking Jason Opperisano
2004-08-27 18:09 ` Michael Sconzo
2004-08-27 18:12 Jason Opperisano

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20040826165702.H1111@net.tamu.edu \
    --to=msconzo@net.tamu.edu \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox