LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 02-05-2010, 12:57 PM   #1
xenny123
LQ Newbie
 
Registered: Aug 2005
Location: UK
Distribution: Slackware
Posts: 6

Rep: Reputation: Disabled
iptables setup - internal / external traffic


Hi,
I'm using Slackware 13, kernel 2.6.29.6-smp. I'm running Apache, MySQL, UPnP server, DAA server, Samba, TorrentFlux and want SSH access.
My server will be placed in the DMZ of my router, and so I would like to drop all traffic from the internet unless it's for:

- Apache (port 80)
- SSH (port 22)
- TorrentFlux (BitTornado, 49160-49300)

But, internally I would like it drop all traffic except for:

- Apache (port 80)
- MySQL (port 3306)
- SSH (port 22)
- Samba (ports 139 and 445)
- DAA Server (3689)
- UPnP Server (5001)

Is this feasable? Or am I missing something crucial? I do know there are mountains of documentation for iptables but I don't have spare time to trawl through it all so any help is much appreciated.
 
Old 02-05-2010, 02:53 PM   #2
Weird0ne
LQ Newbie
 
Registered: Nov 2009
Distribution: Slackware / Arch
Posts: 10

Rep: Reputation: 2
Does your computer have 2 NIC cards?

If not, DMZ on most routers disallow the internal network from accessing the DMZ'd computer since it get's a DHCP address from your ISP.
 
Old 02-05-2010, 03:26 PM   #3
xenny123
LQ Newbie
 
Registered: Aug 2005
Location: UK
Distribution: Slackware
Posts: 6

Original Poster
Rep: Reputation: Disabled
Only the one NIC card, all machines on internal network are able to access the machine in DMZ, it receives IP from router DHCP, so I assume that by DMZ, the router just routes all inbound packets from net to the assigned IP?
Not too sure, but can confirm that all internal machines can access all open ports.
 
Old 02-08-2010, 03:58 AM   #4
xenny123
LQ Newbie
 
Registered: Aug 2005
Location: UK
Distribution: Slackware
Posts: 6

Original Poster
Rep: Reputation: Disabled
If this is not possible, what alternatives for firewall protection are available?
 
Old 02-10-2010, 05:18 PM   #5
Weird0ne
LQ Newbie
 
Registered: Nov 2009
Distribution: Slackware / Arch
Posts: 10

Rep: Reputation: 2
If there's no problem with the internal network reacing the DMZ machine what's preventing a simple iptables firewall?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
iptables redirect all traffic from external ip to internal ip brb_bart Linux - Networking 1 12-17-2009 06:56 PM
Forward traffic from internal NIC to external NIC laurens Linux - Newbie 4 07-30-2009 10:53 AM
Routing internal traffic to external kzsolt Linux - Networking 7 05-21-2009 12:17 PM
setup email client for internal and external mail access shadoxity Linux - Software 15 04-21-2005 08:17 AM
Simple IPTables... Want to pass all data from one external IP to an internal IP AdamRankin Linux - Networking 3 04-01-2003 03:24 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 08:01 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration