LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 10-17-2002, 08:23 AM   #1
antken
Member
 
Registered: Nov 2000
Posts: 368

Rep: Reputation: Disabled
ipchains again


hi,

i am trying to stop one certain ip within my network access to the internet
i am using ipchains, so far i only have one line in there in the forward chain it basically is masqing all trafic from 'anywhere' to 'anywhere'

now i want to ban one ip address: 192.168.56.39

i have tryed ipchains -A forward -s 192.168.56.39 -J DENY

but it does not work i can still get through with all trafic

what have i done wrong?
 
Old 10-17-2002, 01:20 PM   #2
Mara
Moderator
 
Registered: Feb 2002
Location: Grenoble
Distribution: Debian
Posts: 9,696

Rep: Reputation: 232Reputation: 232Reputation: 232
You need to put the line that allows all AFTER the one that denies acces to one machine.
 
Old 10-17-2002, 03:10 PM   #3
antken
Member
 
Registered: Nov 2000
Posts: 368

Original Poster
Rep: Reputation: Disabled
ok

so what you are saying is that ipchains list of things to do should look like:

192.168.56.39 Deny
192.168.0.1 allow
192.168.0.2 allow

and so on


i have been playing around on a box and have found that i can put the machine to be banned in the input chain with the deny rule i have also found i can put sites in the input chain with the destination set to for example microsoft and it blocks the site

would that be a good way to do it?
 
Old 10-17-2002, 03:35 PM   #4
Mara
Moderator
 
Registered: Feb 2002
Location: Grenoble
Distribution: Debian
Posts: 9,696

Rep: Reputation: 232Reputation: 232Reputation: 232
I don't understand the question, I must say...
 
Old 10-17-2002, 03:45 PM   #5
antken
Member
 
Registered: Nov 2000
Posts: 368

Original Poster
Rep: Reputation: Disabled
sorry, just wittering on

i try and make sense of it


my original question was how do i stop internet acess on one machine.

you said make it one of first rules in the chain

i then said i have been playing around and found out that it i put the machine in the input chain i can stop it that way:

ipchains -A input -s 192.168.59.34 -j DENY

would the above be as effective?
 
Old 10-17-2002, 04:52 PM   #6
DavidPhillips
LQ Guru
 
Registered: Jun 2001
Location: South Alabama
Distribution: Fedora / RedHat / SuSE
Posts: 7,163

Rep: Reputation: 58
input is correct
 
Old 10-18-2002, 04:56 AM   #7
Mara
Moderator
 
Registered: Feb 2002
Location: Grenoble
Distribution: Debian
Posts: 9,696

Rep: Reputation: 232Reputation: 232Reputation: 232
Yes, it will be.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Ipchains brokenflea Linux - Networking 1 02-03-2004 05:44 AM
ipchains i.d. Linux - Security 5 08-21-2002 02:12 PM
ipchains help ... please> paulw Linux - Security 3 11-16-2001 10:15 AM
IpChains again ETT Linux - Security 3 07-24-2001 07:49 AM
[ipchains] MrGreg Linux - General 4 07-14-2001 11:35 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 07:42 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration