When iptables stop the machine is a plain router

From: Maurice Hoeneveld (m.hoeneveld_at_hro.nl)
Date: 09/29/04


Date: 29 Sep 2004 14:26:12 -0700

I do use a RedHat 7 hardened machine with with 4 interfaces and
iptables on it as a firewall.
There are several internal networks defined in the routing table of
this machine.

No consider the following;

When I use start iptables the machine acts like a firewall and only
traffic that is allowed in the rules is send trough the firewall. The
rest is blocked ofcourse.

Now something weird happens (at least for a firewall)
When iptables stops working (manual, crashed or bufferoverflow by a
DoS attack) the machine is a plain router/bridge. So all traffic is
allowed based on the available routingtable in the machine.

When I see other firewall systems like Checkpoint for example you can
see that when the firewall processes are killed, the machine also
stops routing and is a kind of stealth environment like it should be
in case of an incident.

Anyone know how to solve this issue because I dont want that when
iptables is stopped my trusted environment is public available.

Thanks for your help and suggestions in advance.

Maurice Hoeneveld
mhoeneveld@zonnet.nl



Relevant Pages

  • Re: Feedback solicited - best way to harden a mail/web server?
    ... Was the system protected by a properly configured firewall? ... it's not a bad "starting point" and it can generate an IPtables rule ... > nor is there a web or ftp server; aside from that I haven't tried to secure ... Before I'll install some nifty application ...
    (comp.os.linux.security)
  • Re: EMERGENCY - need to secure my server against an ongoing SPAMMER
    ... computer with a broadband connection. ... that IP range will prevent that spammer from wasting your systems ... This approach eventually makes your firewall machine so busy it has ... A better approach is to use IPTables to deny ALL inbound attempts to ...
    (Fedora)
  • linux - iptable firewall DNS question
    ... When my firewall is active, i am unable to use name solving features from my ... iptables -P INPUT ACCEPT ... # $ipnet -> adresse ip de l'interface connectée à internet ... echo ACCES AU FIREWALL DEPUIS LOCAL ...
    (comp.security.firewalls)
  • Re: firestarter start failure?
    ... It writes to iptables firewall rules, and then is done, ... unless gui is open. ... Do I have to start Firestarter after I have rebooted? ... When Firestarter is installed from a package, the firewall ...
    (Ubuntu)
  • Clearing up some security "jargon"
    ... The kernel supplies the iptables service, which is by default, ... There is no need to "turn on" a firewall. ... Consider the package "ufw", a tool that some people say can ... Consider Firestarter. ...
    (Ubuntu)