Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Sorin Panca <sorin.panca@gmail.com>
To: Sven Geggus <sven@gegg.us>, netfilter@lists.netfilter.org
Subject: Re: Strange behaviour of REDIRECT/ipt_recent
Date: Sat, 24 Sep 2005 15:56:41 +0300	[thread overview]
Message-ID: <43354D09.40103@gmail.com> (raw)
In-Reply-To: <20050922211815.GA3701@diesel.geggus.net>



Sven Geggus wrote:
> Hi there,
> 
> the following rule works fine so far
> (redirect any connection to a given IP to Port 22):
> 
> iptables -t nat -A PREROUTING  -p tcp ! --dport 22 -d $SSHIP -j REDIRECT \
> --to-port 22
> 
> But now I need to restrict Connections to 3 accesses per minute to prevent
> DOS-Attacken by means of Portscans:
> 
> iptables -A INPUT -i eth0 -p tcp -d $SSHIP -m state --state NEW -m recent \
> --set --name SSH
> iptables -A INPUT -i eth0 -p tcp -d $SSHIP -m state --state NEW -m recent \
> --update --seconds 60 --hitcount 4 --rttl --name SSH -j REJECT \
> --reject-with tcp-reset
> 
> Unfortunately this does not work as expected :(
> 
> It just works on port 22 but not on any other port.
> 
> I suspect that the redirect rule may change the destination IP to the
> default IP of eth0, but I would consider this to be a bug.
> 
> Can you confirm this? workarounds?
> 
> Sven
> 
> P.S.: Please CC me in the reply, because I am not subscribed to the list.
> 
if you want to access your ssh server from behind a transparent squid
proxy, try https (443) and messenger's ports. for yahoo it is 5050. i
did that successfully. i build a ssh tunnel and routed my default gw in
it. it worked like magic.
but beware to add a static route to your previos default gateway,
otherwise you will lose the connection to your sshd server host.
if there are some LANs behind the squid transparent proxy that you need
too access, set static routes for that too. you can put the script to
set up routes and iptables forwarding rules (if you want to be the
gateway for your friends in pain, and have them make you the default
gateway - you will need to set some bandwidth management for them) in
pppd config directory.


      parent reply	other threads:[~2005-09-24 12:56 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-09-22 21:18 Strange behaviour of REDIRECT/ipt_recent Sven Geggus
2005-09-23 12:55 ` /dev/rob0
2005-09-24 12:56 ` Sorin Panca [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=43354D09.40103@gmail.com \
    --to=sorin.panca@gmail.com \
    --cc=netfilter@lists.netfilter.org \
    --cc=sven@gegg.us \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox