Linux Netfilter discussions
 help / color / mirror / Atom feed
* Special firewall for wannabee dmz machine
@ 2007-12-25 13:53 reader
  2007-12-25 16:47 ` G.W. Haywood
  0 siblings, 1 reply; 5+ messages in thread
From: reader @ 2007-12-25 13:53 UTC (permalink / raw)
  To: netfilter

( I've probably irritated the ipfilter list by mistakenly posting this
  there first)

I'd like to see some examples of how to do this:

I'm setting up a gentoo linux machine who's sole purpose is to get
traffic coming to a NETGEAR router upstream.  That router has one of
those options they call DMZ where you can give a lan address machine
to be sent all traffic that is blocked from the lan.

In my case it isn't a true DMZ because it will not route anything to
other parts of the lan.  It's pupose is to drop but log all the
baloney coming at the NETGEAR from the internet.

I just want to poke around in the logs of what is coming my way.

It will only need to communicate to the internet rarely if at all
and then from lynx, or over ssh.  It has no X installed, no services
like apache, samba, cups, etc etc.  Only ssh.  And I'd like that to
only be open to the lan.

I'm confused about which things need to be allowed in and how to
handle the rejected stuff, far as logging only possible nasty stuff
and not normal dns or other normal traffic.


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2007-12-26 17:10 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-12-25 13:53 Special firewall for wannabee dmz machine reader
2007-12-25 16:47 ` G.W. Haywood
2007-12-26  4:14   ` reader
2007-12-26 16:24     ` G.W. Haywood
2007-12-26 17:10       ` reader

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox