[Discuss] Iptables.rules
Cy Schubert
Cy.Schubert at komquats.com
Sun Jul 5 19:19:21 PDT 2015
Show up to the next BB&C Linux SIG and we can discuss firewalls there. (I
think the last time we discussed firewalls at the SIG we got sidetracked
with routing.) I'm not a iptables expert (I'm an ipfilter user under
FreeBSD), the vast majority of what you need to know is a basic
understanding of TCP/IP concepts. The rest is pretty much mechanical.
Another thing you might want to try is fwbuilder from fwbuilder.org. It's
no longer maintained (Net Citadel hired him) but the application still
applies and can build iptables rulesets for you. You will still need a
basic understanding of TCP/IP to set up a basic ruleset.
--
Cheers,
Cy Schubert <Cy.Schubert at komquats.com> or <Cy.Schubert at cschubert.com>
FreeBSD UNIX: <cy at FreeBSD.org> Web: http://www.FreeBSD.org
The need of the many outweighs the greed of the few.
In message <232BF168-4BDB-4F63-9243-D83573B5ADDD at gmail.com>, Jean Taggart
write
s:
>
> Hello All,
>
>
> Is there an Iptables expert that would be willing to sit down and give me a o
> ne on one tutorial on how best to design my iptables.rules file?
>
> I recently came to the conclusion that I have outgrown my DDWRT flashed route
> r. It was ok for it���s time, but I���m in need of greater flexibility.
>
> With this in mind I have purchase a tiny fan less mini pc, that comes equippe
> d with 2 ethernet cards. I installed Debian 7 in text only mode, and quickly
> had everything working for the basic operation as a firewall.
>
> It is only when I tried some fancier iptables manipulations that I hit a road
> block.
>
> here is the basic topology of the network and a quick explanation of what I���m
> trying to achieve;
>
> _____________________________________________________________________________
> _____________________________________________________________________________
> ______________________________________________
>
> The network behind the firewall. The IP address of eth
> 1 The IP address of eth0 The
> network in front of the firewall The
> IP address on the 2nd firewall (it is connected to the internet.)
>
> [192.168.2.0/24]������������������������-------------------------[192.168.2.1]���������������������������������[192.168.1.24]������������������������������������[192.168.
> 1.0/24]���������������������������������������������������������[192.168.1.1]
>
> The IP address of the one machine behind the firewall
> Statically assigned (no DHCP) [192.168.2.1]
>
>
> The SAMBA share I want to ac
> cess 192.168.1.1/mnt
>
> _____________________________________________________________________________
> _____________________________________________________________________________
> ______________________________________________
>
>
>
> This has led me to read a large number of tutorials, FAQ���s, blog posts and for
> ums. While i have learned a ton about Iptables and am able to successfully ac
> cess the share using an iptables.rules that I devised, doing so pretty much o
> pens up the firewall to access ALL the shares located on the 192.168.1.0/24.
> My web research indicates that there is a way to explicitly allow only access
> from a specific host, to a specific share, allowing only the ports needed fo
> r samba, but success has eluded me in this quest so far.
>
> I���m afraid that my web research, while initialy useful may have done more harm
> than good. I am now waiting for several O���reilly books on the subject to arri
> ve from Amazon in a last ditch effort to solve this problem.
>
> I realize that the time of such an expert would be valuable and I���m prepared t
> o pay $100 an hour, with a guaranteed minimum of one hour, and a maximum of 3
> . I need to understand the proper syntax, so that I may have the building blo
> cks to add further rules for greater functionality in the future.
>
> If anyone is up to the challenge, simply email me at this address so that we
> can setup a time that is convenient.
>
> Regards,
>
> Jean Taggart
>
>
> _______________________________________________
> Discuss mailing list
> Discuss at vlug.org
> http://lists.vlug.org/mailman/listinfo/discuss
>
More information about the Discuss
mailing list