LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 02-26-2006, 01:27 AM   #1
gauge73
Member
 
Registered: Jan 2003
Location: Dallas, TX
Distribution: Fedora Core 4
Posts: 420

Rep: Reputation: 30
Easy iptables question (I promise)


I have been editing my iptables script today to add a third interface for a DMZ. After fidgetting with it for a while, I think I've learned something, and I want to be sure that it's accurate.

Previously, I was under the impression that a packet being received on interface A and destined for some other host on the network connected to interface B (i.o.w., the packet is routed through the firewall) would go through the chains in the following order:

1) INPUT
2) FORWARD
3) OUTPUT

Now I believe that I was wrong. I'm noticing that the rules I place in the INPUT chain seem to have no effect on the packets routing through the firewall. Therefore, I am lead to believe that traffic routed through the firewall does not go through the FORWARD chain in addition to the INPUT chain, it goes through the FORWARD chain instead of the INPUT chain. Therefore, such a packet would go through the following order of chains:

1) FORWARD
2) OUTPUT

I did not realize this when setting up my initial firewall script because I didn't really do any filtering in the INPUT chain to speak of. I think that if I'm right about this, however, my INPUT chain is going to need some alteration.

Can you guys please confirm or deny whether or not this "discovery" is accurate? Thanks in advance for any assistance!
 
Old 02-26-2006, 06:32 AM   #2
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
they don't go through the OUTPUT chain either...

INPUT: packets which hit the box and are destined for the box traverse this chain...

OUTPUT: packets which are generated by the box traverse this chain...

FORWARD: packets which hit the box and are destined for another box traverse this chain...

Last edited by win32sux; 02-26-2006 at 06:35 AM.
 
Old 02-26-2006, 02:04 PM   #3
gauge73
Member
 
Registered: Jan 2003
Location: Dallas, TX
Distribution: Fedora Core 4
Posts: 420

Original Poster
Rep: Reputation: 30
Thanks! Apparently, I need to be changing quite a few things in my firewall script.

I didn't really put any restrictions in the INPUT or OUTPUT chains originally, and now that I'm fooling with them (as I'm a bit more security-oriented these days), I'm finding out that my original understanding of iptables is somewhat flawed.

Anyway, thanks again for the reply!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Easy question for ya... speedo Linux - Newbie 2 10-23-2004 04:38 PM
Easy iptables question speed_viper Linux - Networking 1 09-12-2004 11:31 PM
promise S150 tx2plus question kojie Linux - Hardware 2 07-30-2004 01:39 AM
iptables easy to answer question BajaNick Linux - Security 4 09-19-2003 08:22 PM
Mandrake 9.1 and Promise Raid Question natesch Linux - Hardware 3 09-01-2003 07:15 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 11:11 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration