LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-05-2002, 01:12 PM   #1
Stingreen
Member
 
Registered: May 2001
Location: Baltimore,MD,USA,Earth,Some Galaxy, We haven't gone that far!
Distribution: Redhat 7.3
Posts: 104

Rep: Reputation: 15
Iptables Firewall script.


Guys, I need a ipchains or iptables firewall script that should fit the following diagram..

There will be 3 NIC on the firewall server. 1 one of them will open up the internet. One of them for our local network and the last one is for our Servers.. (WEB, DNS , MAIL)
Any luck that I can find a ipchains firewall script suitable for this situation??
Thank you..


INTERNET
|
|
eth2
------------------
|160.75.5.5 | Server Network
| | eth0
| |----------------------------------------------
| LINUX |
| IPCHAINS | 212.2.2.1 | | |
| FIREWALL | | | |
|192.168.1.1 | | | |
----------------- - -------- ------- -------
| eth1 | WWW | |SMTP | |DNS |
|192.168.1.1 -------- ------- -------
| 212.2.2.2 212.2.2.3 212.2.2.4
Local LAN
 
Old 04-05-2002, 03:25 PM   #2
jrmann1999
Member
 
Registered: Feb 2001
Location: Texas
Distribution: Slackware, Mandrake, LFS
Posts: 306

Rep: Reputation: 30
two words:

# man iptables

But seriously, would you ever trust anyone here to fully write a iptables script securely? I sure wouldn't if I was that concerned with security. I'd also like to note that I have *zero* clue what your diagram means. I can assume you have the three nics, of which eth2 is connected to the internet, eth0 connected to a server net, and eth1 connected to a private subnet.

I will be glad to try and help you create your *own* iptables script, but I really need some clarity in your situation.

1. Eth0 subnet is? This nic controls what domain?(Internet, Servers, Private)
2. Eth1 subnet is? This nic controls what domain?
3. Eth2 subnet is? This nic controls what domain?
4. Are all nics in the linux box?
5. Do you want each subnet to hit the internet, as well as each other?
6. Ipchains == Firewall in the case you need. Don't separate them, and use iptables as IMHO it's easier and more secure.
7. Do you only have one Internet IP?

Be very detailed and you'll get answers faster here!

J
7.
 
Old 04-05-2002, 05:19 PM   #3
Stingreen
Member
 
Registered: May 2001
Location: Baltimore,MD,USA,Earth,Some Galaxy, We haven't gone that far!
Distribution: Redhat 7.3
Posts: 104

Original Poster
Rep: Reputation: 15
Oh my god!!
My diagramm..??!??
How the heck did it take that shape? It's not what I drew!. Even I don't have an idea what it looks like..
I'm very sorry bout that.

Ok, let me clear my diagram in my own "words" then..
First of all,
There will be 3 NIC cards in the "same" linux box.
-The first NIC (eth0) will be the only one to be exposed to the internet.
It'll have static IP.
-My second NIC will be serving to my servers. It doesn't need to be connected to the internet seperatly, It'll get it's connection from eth0. (This one has an IP, let's say 192.168.0.1, this NIC will share it's connection via a switch to 3 servers..
-My third NIC card will be used only for my local Network( workstations,print server etc.)

I can use as many static IP's as I want. No restriction is applied in bandwith either.

Gathering all the NIC's under the same domain would be fine?
Or should I seperate them all?
Well, this is the basic idea , what I wanna do.
Thanks in advance.

Last edited by Stingreen; 04-05-2002 at 10:31 PM.
 
Old 04-06-2002, 07:46 PM   #4
Mara
Moderator
 
Registered: Feb 2002
Location: Grenoble
Distribution: Debian
Posts: 9,696

Rep: Reputation: 232Reputation: 232Reputation: 232

I'd give eth2 192.168.1.1 or something similar.
The firewall script you may use is a standard firewalling script (only looking at packets coming from/to eth0). It's harder to configure it toroute well, but not hard. Read man route, man ifconfig and man iptables.
 
Old 04-11-2002, 08:24 AM   #5
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
Try this tutorial...

http://www.linuxsecurity.com/resourc...bles-Tutorial/

There is a DMZ example to try and then adjust for your needs.

Also, make sure you read all the tutorial first, it will save going back several times to follow Oskar's strategy.

Rgds.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Iptables (with masq) troubleshooting, very simple script attached script and logs. xinu Linux - Networking 13 11-01-2007 04:19 AM
Iptables with iptables-firewall.conf arno's matt3333 Slackware 16 06-28-2007 07:20 AM
slackware's /etc/rc.d/rc.firewall equivalent ||| firewall script startup win32sux Debian 1 03-06-2004 09:15 PM
IPTABLES firewall Vs rc firewall netguy2000 Linux - Security 7 02-28-2004 04:31 AM
My iptables script is /etc/sysconfig/iptables. How do i make this baby execute on boo ForumKid Linux - General 3 01-22-2002 07:36 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:32 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration