Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Pascal Hambourg <pascal.mail@plouf.fr.eu.org>
To: netfilter@vger.kernel.org
Subject: Re: Possible IPTables bug in INPUT interface filtering?
Date: Tue, 20 Apr 2010 12:37:36 +0200	[thread overview]
Message-ID: <4BCD83F0.8000906@plouf.fr.eu.org> (raw)
In-Reply-To: <t2w464fbb2d1004191515hd4f9fe2cofe500bab85945682@mail.gmail.com>

John Engelke a écrit :
>>
>>> So this box has two interfaces on the local subnet, eth0 and eth1.
>> Are both interfaces connected to the same subnet ? If so, I don't call
>> this "multihomed".
> 
> According to the link at http://en.wikipedia.org/wiki/Multihoming ,
> this setup can be described as "Multiple Interfaces, Single IP address
> per interface". So I'm actually trying to limit load on one interface
> using IPTables, which is a little different but nonetheless a variant
> on the concept.

You did not clearly answer my question : are both interfaces connected
to the same subnet ? Please detail your network setup.

>>> I would like to restrict VNC to only one of the interfaces, eth1. At
>>> the start, VNC does not work. So I add this:
>>>
>>> -A INPUT -i eth1 -p tcp -m multiport --port 5900 -j ACCEPT
>>>
>>> Then, VNC starts working on eth0 AND eth1.
>> Are you sure ? How do you know ?
> 
> Well I know because I added the line to the iptables rules file in
> /etc/sysconfig and restarted the service. It didn't work before I
> added the line and restarted. I tested both IPs before and after.

This is not proof. As I wrote, either IP address may be used on either
interface. Proof would be some packet capture or iptables log on eth0.

> So are you stating that without providing the IP address that you are
> able to filter solely on the interface name (i.e. -i eth0 or -i eth1)?

Yes, if I want to filter only on the interface. Again, when doing so any
(non loopback) address assigned to any interface is reachable through
that interface, not only the specific address assigned to it.

>> If both interfaces are connected to the same subnet, by default your box
>> accepts packets destined to any local non-loopback address on any
>> interface, including packets destined to the address assigned to eth1 on
>> eth0 and vice versa. This is because Linux enforces the "weak" host model.
> 
> Okay, fine. But I don't see anything in either the man pages for
> IPTables nor in the examples linked from netfilter.org to indicate
> this. If the '-i' interface flag only works under certain conditions
> the documentation ought to state those conditions. I RTFM for this
> one.

I don't see why this needs to be indicated there. This is not related to
netfilter or iptables.

> Bottom line is interface filtering doesn't really work when it
> requires IP/subnet parameters too. Bug or not it's unexpected
> behavior.

It is just unexpected to you because packets don't flow the way you
think. Packets for a given address may arrive on any interface.
Addresses and interfaces are mostly independent.

  reply	other threads:[~2010-04-20 10:37 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2010-04-16  3:12 Possible IPTables bug in INPUT interface filtering? John Engelke
2010-04-16 15:23 ` Pascal Hambourg
2010-04-19 22:15   ` John Engelke
2010-04-20 10:37     ` Pascal Hambourg [this message]
2010-04-21 18:27 ` Narendra Choyal
2010-04-21 21:30   ` Richard Horton
2010-04-21 22:10     ` Jan Engelhardt

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=4BCD83F0.8000906@plouf.fr.eu.org \
    --to=pascal.mail@plouf.fr.eu.org \
    --cc=netfilter@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox