LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 12-04-2007, 12:32 AM   #1
jgtg32a
Member
 
Registered: Feb 2005
Posts: 53

Rep: Reputation: 15
IPtables help


Ok Heres the network layout

I have a "webserver" a P4 w/ 512 ram, and I have a dedicated firewall a AMD3200+ w/ 2gb ram. Both running Ubuntu Desktop ED. Not the best for the firewall but Gentoo was giving me too much grief. This is a class assignment I'm trying to harden it against attacks mainly DoS attacks. I've gone through the Iptables tutorial (http://iptables-tutorial.frozentux.n...-tutorial.html) which was rather helpful.

But one thing that I can't figure out how to do is make my firewall invisible I mean with the +1 to TTL on all packets and all. But I'm having trouble getting the firewall to back off and not grab an the address from the network. Basically I want the firewall to just drop all packets I don't like and the server to use DHCP and grab an IP address. Thats the part I'm having trouble with right now.

Or should I just say forget it and go with NAT and forwarding.

Thank you in advance, and be sure to check back because I've got alot of questions.
 
Old 12-04-2007, 02:55 AM   #2
checkmate3001
Member
 
Registered: Sep 2007
Location: Folsom, California
Distribution: Ubuntu, Mint, Debian, Suse
Posts: 307

Rep: Reputation: 32
Beyond me... but this site could help you setup an iptables script.
http://easyfwgen.morizot.net/gen/

I use it to help me out. I change the settings, have it create the script and then see what it did. I occasionally will modify the scripts to my liking.

May be helpful.
 
Old 12-04-2007, 02:50 PM   #3
dbmacartney
Member
 
Registered: Mar 2007
Location: London, UK
Distribution: Debian, Red Hat Enterprise, Fedora
Posts: 70

Rep: Reputation: 15
could you give a little more detail on network details and which IP you are trying to protect? one way of blocking would be to set your default policy on your tables to drop automatically and then just enable the ones you require for services.

eg: iptables -P INPUT DROP

I hope I can be of more assistance, more details would help :-)
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
An error occured getting IPtables status from the command /etc/rc.d/init.d/iptables s CrazyMAzeY Linux - Newbie 10 08-12-2010 05:25 AM
iptables v1.2.9: Unknown arg `/sbin/iptables' Try `iptables -h' or 'iptables --help' Niceman2005 Linux - Security 4 12-29-2005 08:20 PM
IPtables Log Analyzer from http://www.gege.org/iptables/ brainlego Linux - Software 0 08-11-2003 06:08 AM
iptables book wich one can you pll recomment to be an iptables expert? linuxownt Linux - General 2 06-26-2003 04:38 PM
My iptables script is /etc/sysconfig/iptables. How do i make this baby execute on boo ForumKid Linux - General 3 01-22-2002 07:36 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 05:10 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration