LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-10-2006, 10:27 PM   #1
chibi
Member
 
Registered: Aug 2004
Location: Canada
Distribution: Archlabs
Posts: 65

Rep: Reputation: 15
Advanced ip range blockage with iptables: 58.160.0.0 - 58.175.255.255


Hello,

Up until now I have been just fine with blocking single ips and ip ranges such as 151.203.0.0/16 .

I have a new challenge and I can't seem to figure it out. I have a server crasher who instead of having the first 2 subnets (I believe they are called subnets(subnet.subnet.subnet.subnet?)) static while the last two are dynamic, only his very first subnet is static and the last 3 are dynamic.

I don't really wanna have to block out all the people beginning with their first subnet (58), but I have determined the ip range their ISP is allowed to use.

58.160.0.0 - 58.175.255.255

So what I need to do is block the above range specifically, and I do not really know how to do that. If someone could please help me out I would appreciate it. So far I've always just used this format:

iptables -A INPUT -s 58.160.0.0/16 -j DROP But if I started with 58.160.0.0/16 how would it know to stop at 58.175.0.0/16 ??

Thank you so much !

-Chi

Last edited by chibi; 04-10-2006 at 10:48 PM.
 
Old 04-10-2006, 10:58 PM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
58.160.0.0-58.175.255.255 == 58.160.0.0/12

http://www.subnet-calculator.com/cidr.php
 
Old 04-11-2006, 01:06 AM   #3
chibi
Member
 
Registered: Aug 2004
Location: Canada
Distribution: Archlabs
Posts: 65

Original Poster
Rep: Reputation: 15
Awesome, thank you! That subnet calculator is very handy I extremly appreciate it.

I had this "network" calculator but it doesn't do what the one you gave me does. I was thinking I had to do some extra work to the iptables command, but I guess it would make more sense that it could be represented numerically.

Thanks again
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
iptables - dropping an ip *range* chibi Linux - Security 6 12-17-2005 08:22 PM
ip range in iptables masterlloyd Linux - Security 1 01-11-2005 02:00 AM
specifying a range of IP in IPTABLES jomy Linux - Security 1 12-23-2004 07:30 AM
iptables: source range Carlee Linux - Security 8 09-01-2003 01:38 PM
Advanced Iptables Issue Seather Linux - Networking 5 08-30-2003 07:09 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:46 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration