Linux Netfilter discussions
 help / color / mirror / Atom feed
* block 8080, but redirect from 80 to 8080
@ 2006-08-01  4:11 Dean Hiller
  2006-08-01 10:46 ` Pascal Hambourg
  0 siblings, 1 reply; 5+ messages in thread
From: Dean Hiller @ 2006-08-01  4:11 UTC (permalink / raw)
  To: netfilter

I would like block all traffic to port 8080 except that which was 
redirected in the nat table from port 80 to 8080. 

I have a default policy of DROP on incoming.  The following is what my 
iptables file currently has and this works, EXCEPT that 8080 is left 
open to anyone....

*nat table.....
-A PREROUTING -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 8080

*filter table.....
-A RH-Firewall-1-INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j 
ACCEPT
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m tcp --dport 8080 
-j ACCEPT


but anyone can go to http://<machine>:8080 which I want to disallow.  
How can I fix that?
thanks,
dean


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2006-08-01 12:11 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-08-01  4:11 block 8080, but redirect from 80 to 8080 Dean Hiller
2006-08-01 10:46 ` Pascal Hambourg
2006-08-01 11:42   ` Gáspár Lajos
2006-08-01 12:11     ` Pascal Hambourg
2006-08-01 11:54   ` Gáspár Lajos

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox