Block all outgoing requests from IP. (iptables+OpenVZ)
So here we have.
OpenVZ server setup to run multiple vps. What i want to do is: block all outgoing connections and requests from inside of a vps? How do i correctly do this with an ability to ssh to vps? Beforehand thanks for any advice. |
The basic idea is to allow packets belonging to established connections and those creating new inbound SSH connections and drop everything else.
The iptables rules to implement this depend on which container network interface (venet or veth) you're using. venet distinguishes containers by IP address whereas veth distinguishes by interface. For venet: Code:
# <ip> is container IP address Code:
# <in> is Internet interface |
We are using CentOS as a NH OS and it doesnt have ipt_allow.
If we use DROP instead : iptables -A FORWARD -s IP -j DROP ; it blocks all the connections to vps. What would you suggest instead of ipt_allow? Thanks. |
I'm fairly certain that iptables doesn't support negated filters, so you cant say "DROP all except SSH". You have to say "ALLOW SSH; DROP".
AFAIK the ALLOW, DROP, and REJECT targets are builtins; it's not possible to make an iptables without them. Can you post the error message that tells you that ALLOW isn't available? |
All times are GMT -5. The time now is 10:50 AM. |