LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 10-19-2001, 06:56 AM   #1
jabble
LQ Newbie
 
Registered: Oct 2001
Location: In
Distribution: redhat
Posts: 8

Rep: Reputation: 0
Ipchains ??


i'm facing some problems while workin' with ipcahins.
is it a good firewall for network?

when i implemented some policies with one system,it works fine.
but for network . . . . .
i want to block all outgoin' traffic from port 80.so i implemented the policy on the gateway (giving network mask).
the policy works absolutely fine on a single sys.
but doesn't work on the whole network.

our administrator says that ipchains isn't a very flexible n efficient firewall and rather we shd choose some other one.
what do u people say?

thanks in advance.
jabble.
 
Old 10-19-2001, 08:08 AM   #2
Aussie
Senior Member
 
Registered: Sep 2001
Location: Brisvegas, Antipodes
Distribution: Slackware
Posts: 4,590

Rep: Reputation: 58
What kernel are you using?
 
Old 10-19-2001, 01:31 PM   #3
Griffon26
Member
 
Registered: Sep 2001
Location: The Netherlands
Distribution: Gentoo, Debian, Mandrake, LFS
Posts: 182

Rep: Reputation: 30
I never really got into ipchains much, but now I use iptables (kernel 2.4.x) and the rules are very intuitive (or at least, they can be if you setup your script the right way).

Don't think there is much you can't do with it.

If your administrator claims it's not very flexible, then maybe he can give some examples of things that are hard to do with ipchains. Then you can both see if he's right and also if other solutions are more flexible.
 
Old 10-19-2001, 04:08 PM   #4
Cpare
Member
 
Registered: Aug 2001
Location: Magic City, USA
Distribution: Ubuntu
Posts: 73

Rep: Reputation: 15
I run a RH7.1 router using only IPCHAINS and I am very happy with the protection/access it gives my home network of 6 machines, it even allows me to VPN into the company I work for from my NT4 box(I Know, I Know).
 
Old 10-20-2001, 03:37 AM   #5
jabble
LQ Newbie
 
Registered: Oct 2001
Location: In
Distribution: redhat
Posts: 8

Original Poster
Rep: Reputation: 0
we're using redhat kernel 2.4.x here.
maybe then we aren't implementing it properly if it works properly.

we were just trying to block the outgoing traffic frm some ports from all machines except one on network.
the netwk admin says that either we can block the whole traffic or not block at all or specify each system sigularly.

guess i shd study this properly.
 
Old 10-22-2001, 01:02 AM   #6
DavidPhillips
LQ Guru
 
Registered: Jun 2001
Location: South Alabama
Distribution: Fedora / RedHat / SuSE
Posts: 7,163

Rep: Reputation: 58
you build your chains with an interface or an ip or group of ips.

so if everybody is on one interface you have to use ips to set different rules for users.

To designate a network put -s 192.168.0.0/24 or whatever your network is.


This is very possible and I am using ipchains and iptables now, I have a machine on the internet with iptables and one inside the lan with ipchains.


ipmasqadm is good with ipchains if you want to do port forwarding.

it's not needed with iptables



I am going to be setting up VPN soon.

I will probably set up a vpn connection to my house, but will also need one at work.

I have seen that iptables will not work..

I am hoping this is a myth.

Anybody know for sure.

Last edited by DavidPhillips; 10-22-2001 at 01:05 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Ipchains brokenflea Linux - Networking 1 02-03-2004 05:44 AM
ipchains i.d. Linux - Security 5 08-21-2002 02:12 PM
ipchains help ... please> paulw Linux - Security 3 11-16-2001 10:15 AM
IpChains again ETT Linux - Security 3 07-24-2001 07:49 AM
[ipchains] MrGreg Linux - General 4 07-14-2001 11:35 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 07:07 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration