Re: iptables

From: Parker Morse (morse_at_sinauer.com)
Date: 09/29/03

  • Next message: hanfamily_at_earthlink.net: "used 7.3 updates with 7.3"
    To: rrosa@usp.br
    Date: Mon, 29 Sep 2003 13:45:52 -0400
    
    

    On Monday, Sep 29, 2003, at 07:12 US/Eastern, rrosa@usp.br wrote:
    > My script is ok now! You are right : I need to accept connection FROM
    > port. But
    > I needed the udp rules to samba because without the liberantion samba
    > udp, it
    > didn't work.
    >
    > Only another question, if I put ACCEPT in OUTPUT, don't make sense if
    > I put:
    > iptables -t filter -A OUTPUT -p tcp --dport 515 -j ACCEPT
    > to only accept the output to the printer port?? And here I had to put
    > ...OUTPUT
    > -p tcp --source-port 515 -j ACCEPT ??? And I have to accept the output
    > to my
    > ssh, ok?

    I'm not the best person to be asking about firewalls, but:

    I think you're confused about the way OUTPUT works. It acts on any
    packets sent out by your system. Unless you are concerned about how
    users of your system are going to be using it, you're creating more
    problems than you're solving by having too many rules on OUTPUT. Unlike
    INPUT, where you don't know what's coming in from outside, you're
    better off with a permissive policy (only blocking ports which cause
    trouble, instead of only opening ports you need) on OUTPUT.

    Someone PLEASE correct me if I've got this wrong.

    See <http://www.tldp.org/HOWTO/Firewall-HOWTO.html> and
    <http://www.tldp.org/HOWTO/IPCHAINS-HOWTO.html> for more information.

    pjm

    -- 
    redhat-list mailing list
    unsubscribe mailto:redhat-list-request@redhat.com?subject=unsubscribe
    https://www.redhat.com/mailman/listinfo/redhat-list
    

  • Next message: hanfamily_at_earthlink.net: "used 7.3 updates with 7.3"

    Relevant Pages

    • Re: iptables
      ... I need to accept connection FROM port. ... I needed the udp rules to samba because without the liberantion samba udp, ...
      (RedHat)
    • Re: iptables
      ... I need to accept connection FROM port. ... I needed the udp rules to samba because without the liberantion samba udp, ...
      (RedHat)
    • Re: Correction
      ... Normally to physically disconnect is just a matter of reaching for the ... >> I have an ADSL connection which polls my computer from time to time, ... > disallow each and every port with Windows Firewall? ...
      (microsoft.public.windowsxp.messenger)
    • Re: Using Remote Desktop From an SBS Domain
      ... when you tried to RDP while attached directly to a port on your router? ... Internet to initiate an IP conversation with your computer. ... This situation is different than if you ran your own NAT connection sharing ...
      (microsoft.public.windows.server.sbs)
    • Re: Still cant connect to RWW or OWA remotely
      ... it certainly appears to be something about the SBS configuration. ... Meridian.local Ethernet adapter Local Area Connection: ... Windows SMALL BUSINESS SERVER 2003 Windows IP Configuration ... 192.168.254.254) directly to a port on the router and then ...
      (microsoft.public.windows.server.sbs)