LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
LinkBack Search this Thread
Old 03-31-2009, 05:03 AM   #16
TomS_
LQ Newbie
 
Registered: Apr 2008
Posts: 6

Rep: Reputation: 0

Quote:
Originally Posted by 0x29a View Post
Sorry to pester about this, but I was wondering if you could clarify this statement for me so I can see about implementing it on my network.

Hi Andrew,

My comment is specifically about the network itself, and not any particular application, but...

Say your ISP/Network is assigned the subnet 20.30.40.0/24. At your border routers you would have ingress and an egress ACLs or firewall rules that:

a. only allow traffic into your network if it is destined for an IP in the 20.30.40.0/24 subnet (ingress)
b. only allow traffic out of your network it it comes from an IP in the 20.30.40.0/24 subnet (egress)

This ensures that:

a. you only accept traffic that is destined for a host on your network (usually this isn't an issue because it'll probably just get bounced back out via your default route when your border router realises that it cant actually reach the "bogus" destination, but might end up coming back in again, i.e. routing loop, or might just end up being null routed if there is no default route)
b. more importantly, you wont allow traffic to exit your network where the source address has been spoofed

b is the more important of the two. Traffic shouldn't exit your network from IPs that don't live on it. :-)
 
Old 04-04-2009, 05:57 AM   #17
tux99
LQ Newbie
 
Registered: Mar 2009
Posts: 20

Rep: Reputation: 3
Quote:
Originally Posted by TomS_ View Post
Hi Andrew,


Say your ISP/Network is assigned the subnet 20.30.40.0/24. At your border routers you would have ingress and an egress ACLs or firewall rules that:

a. only allow traffic into your network if it is destined for an IP in the 20.30.40.0/24 subnet (ingress)
b. only allow traffic out of your network it it comes from an IP in the 20.30.40.0/24 subnet (egress)
Now if you could add the the relevant iptables commands for this too, you would make it more likely that someone actually goes through the hassle of implementing this good advice!
 
Old 04-05-2009, 04:15 AM   #18
TomS_
LQ Newbie
 
Registered: Apr 2008
Posts: 6

Rep: Reputation: 0
Quote:
Originally Posted by tux99 View Post
Now if you could add the the relevant iptables commands for this too, you would make it more likely that someone actually goes through the hassle of implementing this good advice!
I would, but unfortunately Im not an iptables man. Im a Cisco ACL man. :-)
 
Old 04-05-2009, 04:44 AM   #19
0x29a
LQ Newbie
 
Registered: Jun 2004
Posts: 16

Rep: Reputation: 0
Quote:
Originally Posted by TomS_ View Post
Say your ISP/Network is assigned the subnet 20.30.40.0/24. At your border routers you would have ingress and an egress ACLs or firewall rules that:

a. only allow traffic into your network if it is destined for an IP in the 20.30.40.0/24 subnet (ingress)
b. only allow traffic out of your network it it comes from an IP in the 20.30.40.0/24 subnet (egress)
Hi Tom,

Thank you for the reply. After I've meditated on this it made sense. I knew you were talking about the network in general. I just need to figure out how to implement this on the firewall I use. I can't imagine being able to implement an ACL that can do this on a bridged 678 running CBOS. :-) My 2620 however...my kingdom for a DSL WIC. :-(

Take care,

Andrew

Last edited by 0x29a; 04-05-2009 at 04:46 AM. Reason: fixed a spelling error.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
ARP Poisoning mudasirm Linux - Networking 9 09-11-2008 06:32 PM
Arp table poisoning cristian1983 Linux - Security 2 12-28-2007 01:31 PM
Arp-poisoning help! zaheer Linux - Networking 5 07-25-2007 10:34 PM
Arp Poisoning yawe_frek Linux - Security 3 05-26-2007 06:13 PM
ArpStar 0.5.0 Defeats ARP poisoning bassdemon Linux - Security 14 02-21-2005 01:32 PM


All times are GMT -5. The time now is 05:29 AM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration