LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software > Linux - Kernel
User Name
Password
Linux - Kernel This forum is for all discussion relating to the Linux kernel.

Notices


Reply
  Search this Thread
Old 07-20-2015, 07:39 AM   #1
jayasri
LQ Newbie
 
Registered: Jul 2015
Posts: 1

Rep: Reputation: Disabled
Smile Nat is not intended for filtering , The use of DROP is therefore prohibited.


I have a router with 4 interfaces
two Ethernet and two wireless i.e eth1 eth2 wireless 1 wireless 2 .
wireless 1 connected to a bridge. so wireless 1 is my public interface and remaining 3 private interfaces.

in router i m trying add prerouting drop rule

iptables -t nat -A PREROUTING -d !169.254.130.132 -j DROP

i m getting error nat is not intended for filtering.

My aim is block private access from public interface.

so i have tried input output forward rules.

i have added input rule but it blocks my router access from private interface .
i have added forward rule but it blocks my bridge access from private network.

i want a rule like this

this will break the access, rule should be something like "for packets received on wireless/WAN interface from Outside if destination IP Address is not matching with WAN IP address, then drop the packets"

how to do this without breaking any access.


please reply As soon as possible,plzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz

Thanks in advance.

Last edited by jayasri; 07-20-2015 at 07:44 AM.
 
Old 07-20-2015, 07:59 AM   #2
smallpond
Senior Member
 
Registered: Feb 2011
Location: Massachusetts, USA
Distribution: Fedora
Posts: 4,140

Rep: Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263Reputation: 1263
Why would it receive any packets that don't match its address?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Drop in nat postrouting Tekiano Linux - Networking 1 11-13-2012 04:35 AM
[SOLVED] CentOS 5.8 NAT router icmp unreachable admin prohibited problem kenneth_phough Linux - Networking 6 08-09-2012 08:14 AM
[SOLVED] iptables NAT and DROP question raevin Linux - Security 24 08-08-2011 11:07 AM
filtering XML using XSLT via drop down box esteeven Programming 2 08-22-2009 12:23 PM
iptables: use of DROP in nat table Robert S Linux - Security 2 04-24-2009 12:07 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software > Linux - Kernel

All times are GMT -5. The time now is 09:49 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration