LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
Search this Thread
Old 08-24-2004, 10:12 PM   #1
thelR
LQ Newbie
 
Registered: Aug 2004
Location: Philippines
Distribution: Fedora, Red Hat
Posts: 4

Rep: Reputation: 0
RedHat Linux 9's built-in iptables file


Hello guys!

This is my first try configuring a linux box to serve as an internet server for about 75 PCs in our office. I am using a Red Hat Linux 9 distribution with kernel 2.4.20-8, and iptables ver. 1.2.7a. I need to create a customized iptables script to allow our private network to access the internet using NAT or masquerading since we have only one official IP address assigned. The built-in iptables file in the directory /etc/sysconfig/iptables cannot be customized. It can only be modified with its features using the "lokkit" utility for allowing incoming packets such as HTTP and Mail but it has no feature for doing NAT or MASQUERADING. I tried manually editing the /etc/sysconfig/iptables file and did a /etc/init.d/iptables restart but it did not work. It only issued a "Bad argument 'iptables'" error and a "Try 'iptables-restore' and a [FAILED] message instead of [OK] it if started normal. How do I go about this? I replaced the built-in iptables file with the one I created but it also does not work. Please advise.

Thanks.

thelR

Last edited by thelR; 08-24-2004 at 10:20 PM.
 
Old 08-24-2004, 11:58 PM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 57
The /etc/sysconfig/iptables file shouldn't ever be directly modified. It's extremely sensitive to syntax and certain rules will not work even if the syntax is 100% correct. Instead enter the iptables rules on the command line, verify that everything works to your liking, then do service iptables save. That will modify the iptables file for you.

FWIW, you should just need to do something like this from the commandline (as root):
iptables -A POSTROUTING -o <external_interface> -j MASQUERADE

May or may not need these as well:
iptables -I FORWARD -i <external_interface> -o <internal_interface> -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -I FORWARD -i <internal_interface> -o <external_interface> -j ACCEPT

Also make sure that packet forwarding is on:
echo 1 > /proc/sys/net/ipv4/ip_forward
 
Old 08-26-2004, 03:51 AM   #3
thelR
LQ Newbie
 
Registered: Aug 2004
Location: Philippines
Distribution: Fedora, Red Hat
Posts: 4

Original Poster
Rep: Reputation: 0
Re: RedHat Linux 9's built-in iptables file

Thanks a lot Capt_Caveman, I can now proceed with configuring our linux box.

Last edited by thelR; 08-26-2004 at 04:01 AM.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Redhat 9's autotools broken for apache, mysql, php? rylan76 Linux - Software 0 04-15-2004 03:48 PM
pls help - movie player built in Redhat 9 sanjaya Linux - Software 2 02-13-2004 02:07 AM
Redhat In built firewall quozt Linux - General 1 07-30-2003 12:32 PM
OpenOffice in Slack 9's gnome dbkluck Slackware 1 07-17-2003 04:02 AM
iptables - module, or built into kernel? dunkyb Linux - General 3 02-16-2003 06:04 PM


All times are GMT -5. The time now is 10:46 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration