Re: OT iptables question

From: Marty (martyb_at_ix.netcom.com)
Date: 09/05/05

  • Next message: Rick Pasotto: "canceling apt-get install"
    Date: Sun, 04 Sep 2005 18:57:58 -0400
    To: debian list <debian-user@lists.debian.org>
    
    

    Glenn English wrote:
    > I'm updating a RH ipchains packet filter script from the dim past to
    > iptables on Debian stable.
    >
    > I noticed that when I specified the network the host is on (by IP/mask),
    > the iptables listing called it "localnet." So I tried using localnet in
    > the rule, and iptables seems to take it, and the chain seems to work.
    > But I can't find any documentation about that keyword in man, in Rusty's
    > HTML dox, or with google (lots of talk about it, but no dox).
    >
    > Is localnet a legit iptables network specification or an undocumented
    > feature? What does it actually do (should I hang a CIDR mask on the end,
    > or would that be redundant)? If the host responds to several IPs, does
    > localnet cover then all? Or just eth0? How about eth0:1?
    >
    > It would be very handy because this script is to set filtering on all my
    > DMZ and LAN hosts (by switching on their hostnames and IPs). I know I
    > could just try it and see if it works, but this is to be the packet
    > filter on the DMZ, and I'd like to do it as rigorously as I can.
    >
    > TIA...
    >

    On my sarge system localnet seems to be defined in /etc/networks.
    Try "man networks" You might also try changing the network name there
    and see what happens.

    This raises another question for me, I don't understand why I cannot find the
    this file using dlocate or apt-file, or even using the package search tool on
    debian.org.

    -- 
    To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org 
    with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
    

  • Next message: Rick Pasotto: "canceling apt-get install"

    Relevant Pages

    • Re: Getting access out through gateway
      ... I can't see that the REJECT target at the end of the chain in the filter ... table is the main part of the problem because when iptables are stopped, ... Something in the network setup is awry. ... I see on the gateway 192.168.0.0/24 is defined in the rules and on the ...
      (Fedora)
    • Re: Bridging network adapters in Linux
      ... ip addr add $address/$netbits dev br0 ... Either a default route ... two network devices assuming, ... This is done using the iptables mechanism. ...
      (comp.os.linux.networking)
    • Re: March 29, 2006 total eclipse - IT admins WORST NIGHTMARE
      ... and NewsProxy is the answer for that. ... > Comcast news server. ... simply filters out what I dont want on the network. ... NewsProxy - Network level killfile and content filter for Usenet. ...
      (comp.security.firewalls)
    • Re: Questions on some wierd /var/log entries
      ... How do I find out if I'm on an ipv6 network? ... That is because I prefer using iptables directly. ... then you should start learning about its firewall ... Another important restriction for ssh is to authenticate by certificate ...
      (comp.os.linux.misc)
    • Re: newbie needs help with iptables basics (please)
      ... >I have RTFM (man iptables) and have read several docs off the net and pages ... Implement Multi-Router Traffic Grapher to establish network ... discuss & plan the implementation of Snort 2.0 Intrustion ... Install Snort 2.0 Network-based Intrusion Detection System ...
      (comp.os.linux.security)