LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-10-2010, 10:54 AM   #1
replica88
Member
 
Registered: Nov 2009
Posts: 48

Rep: Reputation: 18
ubuntu firewall, only allow access to port from local network


Below are the rules currently on the firewall,

Code:
root@Fileserver:/# ufw status
Firewall loaded

To                         Action  From
--                         ------  ----
22:tcp                     ALLOW   Anywhere
22:udp                     ALLOW   Anywhere
21:tcp                     ALLOW   Anywhere
21:udp                     ALLOW   Anywhere
20:tcp                     ALLOW   Anywhere
20:udp                     ALLOW   Anywhere
901:tcp                    ALLOW   Anywhere
901:udp                    ALLOW   Anywhere
139:tcp                    ALLOW   Anywhere
139:udp                    ALLOW   Anywhere
445:tcp                    ALLOW   Anywhere
445:udp                    ALLOW   Anywhere
999:tcp                    DENY    Anywhere
999:udp                    DENY    Anywhere
what I would like to do is to only allow access to ports 139,445 from the local network, for example 192.168.1.0. The catch is this system will be reproduced and sent to networks with different address schemes and will get its address via dhcp, ideally I want to avoid manually editing each rule for every system sent out.

Any ideas?

Last edited by replica88; 02-10-2010 at 11:17 AM.
 
Old 02-11-2010, 05:31 AM   #2
Web31337
Member
 
Registered: Sep 2009
Location: Russia
Distribution: Gentoo, LFS
Posts: 399
Blog Entries: 71

Rep: Reputation: 65
You may want to use a shell/perl/python script that will get ifconfig outputs, will generate rules, fits your needs, when first installed on remote system. If i got it right.
 
Old 02-11-2010, 06:30 AM   #3
replica88
Member
 
Registered: Nov 2009
Posts: 48

Original Poster
Rep: Reputation: 18
Quote:
Originally Posted by Web31337 View Post
You may want to use a shell/perl/python script that will get ifconfig outputs, will generate rules, fits your needs, when first installed on remote system. If i got it right.
That sounds like a good idea, it would have to be a script that ran every hour or so to ensure that if the addressing scheme changes and the server leases a new IP the resources are still accessible
 
Old 02-11-2010, 06:34 AM   #4
Web31337
Member
 
Registered: Sep 2009
Location: Russia
Distribution: Gentoo, LFS
Posts: 399
Blog Entries: 71

Rep: Reputation: 65
And don't forget port 135 as well if you're dealing with netbios. That may be vulnerable.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Access Local Port on Website Garibaldi3489 Linux - Networking 1 11-29-2007 01:43 PM
CentoOS router/firewall prob - local network works but router can't access Internet elementalvoid Linux - Networking 6 12-12-2006 03:39 PM
Firewall : port access consty Linux - Networking 1 06-29-2006 03:48 AM
Need access at xebian.localdomain.local for port 21... but I have no clue Kaito 2075 Linux - Newbie 0 02-25-2005 05:22 PM
Suse 9.0 Firewall not allowing local access gSalsero Linux - Security 3 04-19-2004 09:24 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:17 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration