LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 11-19-2013, 05:12 PM   #1
phoenixzam
LQ Newbie
 
Registered: Nov 2013
Location: Texas
Distribution: Fedora & CentOS
Posts: 5

Rep: Reputation: Disabled
Question iptables rule on Fedora13 doesn't make sense


I presume iptables discussions normally go into the Security forum, but this question has more to do syntax and meaning.
The rule is:
Code:
iptables -A INPUT -d 192.168.1.255/32 -i 192.168.168.255 -j ACCEPT
Question:
What does this really do? I don't get the -d & -i option values. For the interfaces here it provides IP addresses (specifically broadcast addresses). How is an interface identified by a broadcast address? Does it reflect the interfaces on this box that would receive the broadcast packets sent to those addresses?
 
Old 11-19-2013, 06:05 PM   #2
John VV
LQ Muse
 
Registered: Aug 2005
Location: A2 area Mi.
Posts: 17,624

Rep: Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651
Fedora 13 is dead and 6 or7 versions out of date
fedora 19 is the current and fedora 20 will ne released soon


please install fedora 19
then worry about the firewall

and you are allowing that ip address

Last edited by John VV; 11-19-2013 at 06:07 PM.
 
Old 11-20-2013, 08:40 AM   #3
phoenixzam
LQ Newbie
 
Registered: Nov 2013
Location: Texas
Distribution: Fedora & CentOS
Posts: 5

Original Poster
Rep: Reputation: Disabled
Uh, that seems a little rude. Yes, I KNOW it is out of date, but simply installing Fedora 19 is by NO means an option. This box is in service. Besides, what does it being a Fedora 13 box have to do with interpreting this iptables commmand? Are you saying that if I have a question about our Fedora 2 box, I'll have to upgrade it before you'll help me?
I may be new to Linux Server administration, but I know you don't have to have the latest version of ANYTHING if what you have does the job. This box does the job it was built to do by the original admin, I just need to understand what that is. Interpreting this line is part of understanding how it firewalls a section of our network. Okay?

So you're saying it is "allowing that ip address" and I think I understand what you mean, you're deciphering the -d option. But what about the -i?
When I read it like a sentence, "If the destination of an incoming packet is 192.168.1.255/32, and it came in through interface 192.168.168.255, then accept it," that part about "through interface 192.168.168.255" still makes no sense to me. And what about the /32 on the destination broadcast address? Can you please explain further without instructing me to upgrade my server OS?
 
Old 11-20-2013, 11:12 AM   #4
DavidMcCann
LQ Veteran
 
Registered: Jul 2006
Location: London
Distribution: PCLinuxOS, Debian
Posts: 6,139

Rep: Reputation: 2314Reputation: 2314Reputation: 2314Reputation: 2314Reputation: 2314Reputation: 2314Reputation: 2314Reputation: 2314Reputation: 2314Reputation: 2314Reputation: 2314
A quick check on the internet reveals
https://frozentux.net/iptables-tutor...-tutorial.html
https://www.informit.com/articles/ar...21057&seqNum=4
I hope they do the trick: I haven't had the stamina to read them!
 
Old 11-20-2013, 11:18 AM   #5
phoenixzam
LQ Newbie
 
Registered: Nov 2013
Location: Texas
Distribution: Fedora & CentOS
Posts: 5

Original Poster
Rep: Reputation: Disabled
Thanks, but no. Doesn't give me the info I looking for. However, I really appreciate you trying to help.

Can anyone tell me, is it possible for iptables to identify the incoming interface using a broadcast address? Because that is what seems to be happening in the code above.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
something doesn't make sense for me in Slackare...libraries.. disco_slack Slackware 7 07-20-2011 07:44 AM
*sigh* I messed everything up again. But this time it doesn't really make sense to me Cultist Debian 12 08-01-2010 10:10 PM
This just doesn't make any sense! FreezEy Debian 8 04-18-2006 08:35 PM
URGENT: netmask doesn't make sense ioncristi Linux - Networking 7 01-28-2006 07:22 AM
netmask doesn't make sense ioncristi LinuxQuestions.org Member Intro 1 01-14-2006 11:23 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 05:43 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration