LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-16-2004, 09:27 PM   #1
Jacky1668
LQ Newbie
 
Registered: May 2004
Posts: 2

Rep: Reputation: 0
Question Rules before DNAT


I have setup the firewall to run DNAT from internet to a server in DMZ for HTTP and SMTP,
Is it possible to block some source ips before it cann dnat to my the sever in dmz? I found that after i run the dnat rules, the rule ( iptables - I INPUT -i eth0 -s abc.xxxx.xxx.zzz -j DROP) cannot block the access from abc.xxx.xxx.zzz to my email server.

Regards
 
Old 05-17-2004, 03:41 AM   #2
ppuru
Senior Member
 
Registered: Mar 2003
Location: Beautiful BC
Distribution: RedHat & clones, Slackware, SuSE, OpenBSD
Posts: 1,791

Rep: Reputation: 50
You can

#iptables -t nat -A PREROUTING -s <source ip> -j DROP

to keep unwanted visitors out of your net.
 
Old 05-17-2004, 10:16 PM   #3
Jacky1668
LQ Newbie
 
Registered: May 2004
Posts: 2

Original Poster
Rep: Reputation: 0
Thanks. Problem solved.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
dnat problem jelgavchik Linux - Networking 0 01-20-2005 06:35 AM
dnat kapcreations Linux - Networking 1 12-28-2004 04:12 PM
IP Tables DNAT hakcenter Linux - Networking 5 11-02-2003 10:35 PM
DNAT won't work taylor Linux - Security 0 10-02-2001 06:36 PM
Viruses, ipchains, dynamic rules, rules with regular expressions marktaff Linux - Security 2 09-25-2001 04:01 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:54 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration