LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 11-06-2015, 06:42 PM   #1
greenace92
Member
 
Registered: Nov 2015
Posts: 70

Rep: Reputation: Disabled
Your iptables rules for Debian 8 Apache 2.4.17 general webserver


I'm pretty early into web developing, about a year now, I'm really concerned about security.

I have a firewall through my provider, and apparently this takes priority over the os-iptables.

I don't know if you run a webserver, if you look at some website or if there is a list of rules up to date on vulnerabilities.

I'd appreciate anything you can contribute.
 
Old 11-06-2015, 07:15 PM   #2
berndbausch
LQ Addict
 
Registered: Nov 2013
Location: Tokyo
Distribution: Mostly Ubuntu and Centos
Posts: 6,316

Rep: Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002Reputation: 2002
The firewall around your machine takes precedence over the internal firewall, in the sense that ports that are closed on the outside firewall can't be reached even if you open them on the inside firewall. But somebody may be able to circumvent the outside firewall, so that it does make sense to set up an internal one as well.

You want iptables rules for a web server? Close all ports, then open 22, 80 and (if you use https) 443.

You want a list of vulnerabilities? I guess Apache has a mailing list for that, as has your OS provider, and bodies like SANS. Check with them.
And don't think that iptables alone makes your system secure. There are plenty of ways to infect your system via a legitimate port.
 
Old 11-06-2015, 07:20 PM   #3
Sefyir
Member
 
Registered: Mar 2015
Distribution: Linux Mint
Posts: 634

Rep: Reputation: 316Reputation: 316Reputation: 316Reputation: 316
You might find this thread useful
http://www.linuxquestions.org/questi...61/#post222579
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
iptables performance causing Apache webserver lockup LastBoyScout Linux - Networking 2 09-08-2015 09:40 AM
General iptables rules questions veeruk101 Linux - Newbie 2 10-27-2011 07:47 AM
trouble reloading iptables rules in Debian dave247 Linux - Security 6 01-25-2011 11:29 AM
Apache and iptables rules abolishtheun Linux - Security 3 10-10-2008 07:48 AM
Where to put iptables rules from Red Hat in Debian aubrey Debian 2 03-03-2004 06:36 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 07:18 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration