Linux Netfilter discussions
 help / color / mirror / Atom feed
From: "ctg60 ctg60" <ctg60@msn.com>
To: netfilter@lists.netfilter.org
Subject: Combination of state match and source/destination match problem.
Date: Wed, 04 Aug 2004 20:26:59 +0800	[thread overview]
Message-ID: <BAY11-F4AkOhw2RlC6a000063d2@hotmail.com> (raw)

Hi all,

Sorry for my English.

I just want to figure out the relation between state match and IP address 
(source and destination ) match of iptables.  And my Redhat 9.0 box which 
has a static IP address of 192.168.220.8 has a ssh service runing on tcp 
port 22.  And my client Linux box with
IP address 192.168.220.6 try to ssh my RH9 box.

Here is my simple iptables rule on 192.168.220.8.

#iptables -F
#iptables -F -t nat
#iptables -F -t mangle
#iptables -P INPUT DROP
#iptables -A INPUT -m state --state ESTABLISHED -j ACCEPT
#iptables -A INPUT -s 192.168.220.6 -j ACCEPT

To my understanding, the INPUT chain of 192.168.220.8 box here deny all the 
external NEW connetions INCLUDING connetions from 192.168.220.6. And the 
result is exact what
I expected. I can't ssh my RH9 box from 192.168.220.6 as well as other 
boxes.

But when I change the iptables to:
#iptables -F
#iptables -F -t nat
#iptables -F -t mangle
#iptables -P INPUT DROP
#iptables -A INPUT -m state --state ESTABLISHED -j ACCEPT
#iptables -A INPUT -d 192.168.220.8 -j ACCEPT

This time it works, I can ssh 192.168.220.8 from 192.168.220.6. Even when I 
replace the last rule with
#iptables -A INPUT -p tcp --dport 22 -j ACCEPT
it also works.

So this time it means INPUT chain of 192.168.220.8 box here deny all the 
external NEW connetions EXCEPT connetions to 192.168.220.8 OR destination 
port 22.
But this conflicts with previous one. According to the previous example this 
doesn't work.

So my question is what's the relation between state match and 
source/destination match?
Or maybe which one comes first or who's seting overwrite the other?

It makes me confused.And it's really hard for me to look into the kernel 
source for answers.

Thanks and Regards,
George Ma

_________________________________________________________________
MSN 8 with e-mail virus protection service: 2 months FREE* 
http://join.msn.com/?page=features/virus



             reply	other threads:[~2004-08-04 12:26 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-08-04 12:26 ctg60 ctg60 [this message]
2004-08-04 12:47 ` Combination of state match and source/destination match problem Antony Stone
  -- strict thread matches above, loose matches on Subject: below --
2004-08-04 12:49 Jason Opperisano
2004-08-05 14:01 ctg60 ctg60

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=BAY11-F4AkOhw2RlC6a000063d2@hotmail.com \
    --to=ctg60@msn.com \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox