Firewall protection for the linux box

Traffic is allowed thru for ssh, http, samba

The config file is /etc/sysconfig/iptables


:FORWARD ACCEPT [0:0]
:INPUT ACCEPT [0:0]
:OUTPUT ACCEPT [3822:803887]
:RH-Firewall-1-INPUT - [0:0]
-A FORWARD -j RH-Firewall-1-INPUT 
-A INPUT -p tcp -m multiport --dports 139,445 -j ACCEPT 
-A INPUT -p udp -m multiport --dports 137,138 -j ACCEPT 
-A INPUT -j RH-Firewall-1-INPUT 
-A OUTPUT -p udp -m multiport --sports 137,138 -j ACCEPT 
-A OUTPUT -p tcp -m multiport --sports 139,445 -j ACCEPT 
-A RH-Firewall-1-INPUT -i lo -j ACCEPT 
-A RH-Firewall-1-INPUT -p icmp -m icmp --icmp-type any -j ACCEPT 
-A RH-Firewall-1-INPUT -p ipv6-crypt -j ACCEPT 
-A RH-Firewall-1-INPUT -p ipv6-auth -j ACCEPT 
-A RH-Firewall-1-INPUT -d 224.0.0.251 -p udp -m udp --dport 5353 -j ACCEPT 
-A RH-Firewall-1-INPUT -p udp -m udp --dport 631 -j ACCEPT 
-A RH-Firewall-1-INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT 
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m tcp --dport 26 -j ACCEPT 
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m tcp --dport 27 -j ACCEPT 
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m tcp --dport 80 -j ACCEPT 
-A RH-Firewall-1-INPUT -p tcp -m state --state NEW -m tcp --dport 8181  -j ACCEPT
-A RH-Firewall-1-INPUT -j REJECT --reject-with icmp-host-prohibited 

# NFS stuff for SFU
# -A INPUT  -s 192.168.1.25 -p icmp -m icmp --icmp-type 3 -j ACCEPT
-A INPUT -s 192.168.1.25 -p tcp -m tcp --dport 111 -j ACCEPT
-A INPUT -s 192.168.1.25 -p udp -m udp --dport 111 -j ACCEPT
-A INPUT -p tcp -m tcp -s 192.168.1.25 --dport 2049 -j ACCEPT
-A INPUT -p udp -m udp -s 192.168.1.25 --dport 2049 -j ACCEPT
-A INPUT -s 192.168.1.25 -p tcp -m tcp --dport 33333 -j ACCEPT
-A INPUT -s 192.168.1.25 -p udp -m udp --dport 33333 -j ACCEPT

COMMIT

I don’t fully understand iptables yet, so keep questions to a minimum.

 
ipsetup.txt · Last modified: 2005/12/28 13:15 by trinisan
 
Recent changes RSS feed Creative Commons License Donate Powered by PHP Valid XHTML 1.0 Valid CSS Driven by DokuWiki