From: "ctg60 ctg60" <ctg60@msn.com>
To: netfilter@lists.netfilter.org
Subject: Combination of state match and source/destination match problem.
Date: Wed, 04 Aug 2004 20:26:59 +0800 [thread overview]
Message-ID: <BAY11-F4AkOhw2RlC6a000063d2@hotmail.com> (raw)
Hi all,
Sorry for my English.
I just want to figure out the relation between state match and IP address
(source and destination ) match of iptables. And my Redhat 9.0 box which
has a static IP address of 192.168.220.8 has a ssh service runing on tcp
port 22. And my client Linux box with
IP address 192.168.220.6 try to ssh my RH9 box.
Here is my simple iptables rule on 192.168.220.8.
#iptables -F
#iptables -F -t nat
#iptables -F -t mangle
#iptables -P INPUT DROP
#iptables -A INPUT -m state --state ESTABLISHED -j ACCEPT
#iptables -A INPUT -s 192.168.220.6 -j ACCEPT
To my understanding, the INPUT chain of 192.168.220.8 box here deny all the
external NEW connetions INCLUDING connetions from 192.168.220.6. And the
result is exact what
I expected. I can't ssh my RH9 box from 192.168.220.6 as well as other
boxes.
But when I change the iptables to:
#iptables -F
#iptables -F -t nat
#iptables -F -t mangle
#iptables -P INPUT DROP
#iptables -A INPUT -m state --state ESTABLISHED -j ACCEPT
#iptables -A INPUT -d 192.168.220.8 -j ACCEPT
This time it works, I can ssh 192.168.220.8 from 192.168.220.6. Even when I
replace the last rule with
#iptables -A INPUT -p tcp --dport 22 -j ACCEPT
it also works.
So this time it means INPUT chain of 192.168.220.8 box here deny all the
external NEW connetions EXCEPT connetions to 192.168.220.8 OR destination
port 22.
But this conflicts with previous one. According to the previous example this
doesn't work.
So my question is what's the relation between state match and
source/destination match?
Or maybe which one comes first or who's seting overwrite the other?
It makes me confused.And it's really hard for me to look into the kernel
source for answers.
Thanks and Regards,
George Ma
_________________________________________________________________
MSN 8 with e-mail virus protection service: 2 months FREE*
http://join.msn.com/?page=features/virus
next reply other threads:[~2004-08-04 12:26 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2004-08-04 12:26 ctg60 ctg60 [this message]
2004-08-04 12:47 ` Combination of state match and source/destination match problem Antony Stone
-- strict thread matches above, loose matches on Subject: below --
2004-08-04 12:49 Jason Opperisano
2004-08-05 14:01 ctg60 ctg60
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=BAY11-F4AkOhw2RlC6a000063d2@hotmail.com \
--to=ctg60@msn.com \
--cc=netfilter@lists.netfilter.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox