Re: iptables - how would you do this?

martin.woolley_at_misys.com
Date: 07/06/05


Date: 6 Jul 2005 00:38:53 -0700


> set the default policy to drop (which you should do anyways)

We tried that and nothing would work, ie we couldn't even log into the
box let alone get our thin clients to come up.

> Your rule is droping all "udp" packets to ports 67 & 68 not rejecting them.

Clearly it isn't, as i/p addresses are still being issued by the
machine.

> Why are you even using dhcp if you are only accepting 6 connections ???

Obviously we have many more than six connections; this is just a snip
from our iptables. AFAIK a thin client must issue a DCHP request
otherwise TFTP won't deliver a kernel to the client.

--
Regards
Martin Woolley
ICT Support
Handsworth Grammar School
Isis Astarte Diana Hecate Demeter Kali Inanna


Relevant Pages

  • Re: iptables - how would you do this?
    ... > box let alone get our thin clients to come up. ... policy is used after all rules in a chain are tried. ... so it will simply give you a message and not disrupt the ...
    (comp.os.linux.networking)
  • Re: recommendation for OU structure
    ... You need a separate Terminal Services profile for the users, and a Loopback ... and the Citrix servers need an OU or a security group filter where the ... loopback policy will be applied. ... Our main facility has pcs with some thin clients. ...
    (microsoft.public.windows.server.active_directory)
  • Re: iptables - how would you do this?
    ... >>set the default policy to drop ... > box let alone get our thin clients to come up. ... Clearly your total iptables is screwed up and as you did not disclose ... AFAIK a thin client must issue a DCHP request ...
    (comp.os.linux.networking)