LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-29-2003, 01:41 PM   #1
Carlee
LQ Newbie
 
Registered: Aug 2003
Posts: 9

Rep: Reputation: 0
iptables: source range


How should I specify the source to be blocked when it is a range?

Examples: 219.154.00 through 219.157.255.255
or 218.2.0.0 through 218.2.15.255.

Is there a better way to exclude all users of ChinaNet?

Thanks.
 
Old 08-29-2003, 05:47 PM   #2
Looking_Lost
Senior Member
 
Registered: Apr 2003
Location: Eire
Distribution: Slackware 12.0, OpenSuse 10.3
Posts: 1,120

Rep: Reputation: 45
Put a hyphen inbetween 'em

219.154.00-219.157.255.255


Don't know of any other practical way to do what you want to
 
Old 08-29-2003, 06:28 PM   #3
Carlee
LQ Newbie
 
Registered: Aug 2003
Posts: 9

Original Poster
Rep: Reputation: 0
A hyphen generates an error when entered:

"iptables v. 1.2.8: host/network '210.154.00-219.157.255.255' not found"

A forward slash doesn't work either (It's saved, but doesn't block the range.)

Thanks for thinking about this.
 
Old 08-29-2003, 06:37 PM   #4
Looking_Lost
Senior Member
 
Registered: Apr 2003
Location: Eire
Distribution: Slackware 12.0, OpenSuse 10.3
Posts: 1,120

Rep: Reputation: 45
I've a cut 'n' paste typing error there

210.154.00.00-219.157.255.255

Does that make any difference, if not maybe can only do ranges in the same network range
 
Old 08-29-2003, 06:55 PM   #5
Carlee
LQ Newbie
 
Registered: Aug 2003
Posts: 9

Original Poster
Rep: Reputation: 0
Doesn't work.

(I'd typed right when I tested, just skipped the decimal here. Sorry.)

What do you mean by "same network range"? Would there be some way to break the full range into several entries?

Also, 'man iptables' had something I didn't understand about masking. Is that relevant?

I haven't been able to find anything searching. This is beginning to look harder than it should be.
 
Old 08-29-2003, 07:03 PM   #6
Looking_Lost
Senior Member
 
Registered: Apr 2003
Location: Eire
Distribution: Slackware 12.0, OpenSuse 10.3
Posts: 1,120

Rep: Reputation: 45
That's what I was thinking about when I mentioned network range, you'll have a few more entries, one line and rule for each but

210.154.0.0/16
211.0.0.0/8
212.0.0.0/8
....
219.157.0.0/16

that sort of thing.
 
Old 08-29-2003, 08:23 PM   #7
Carlee
LQ Newbie
 
Registered: Aug 2003
Posts: 9

Original Poster
Rep: Reputation: 0
Does the "/16" mean that the address is interpreted as everything beginning with 210.154, going to 210.154.155.155? "Masking" the last two groups of numbers?

Why "16?"

To designate the range 218.2.0.0 to 218.2.15.255, would it be "218.2.1.0/4" (with 15 related entries) ?
 
Old 08-31-2003, 04:19 AM   #8
ppuru
Senior Member
 
Registered: Mar 2003
Location: Beautiful BC
Distribution: RedHat & clones, Slackware, SuSE, OpenBSD
Posts: 1,791

Rep: Reputation: 50
It cannot be 218.2.0.0/4.

It can be 218.2.0.0/16 but that will allow add the address from
218.2.0.0 to 218.2.255.255. As you only want IPs from 218.2.0.0 thru 218.2.15.255, it mmust be 218.2.0.0/20.
 
Old 09-01-2003, 01:38 PM   #9
Carlee
LQ Newbie
 
Registered: Aug 2003
Posts: 9

Original Poster
Rep: Reputation: 0
Thanks for your help.

iptables is now blocking 100% of ChinaNet, about 1,000/day.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
iptables - dropping an ip *range* chibi Linux - Security 6 12-17-2005 08:22 PM
iptables allowing a range adm1329 Linux - Networking 2 02-01-2005 01:04 PM
ip range in iptables masterlloyd Linux - Security 1 01-11-2005 02:00 AM
specifying a range of IP in IPTABLES jomy Linux - Security 1 12-23-2004 07:30 AM
how to do this.. IPTABLES IP Range DROP latino Linux - Security 1 01-02-2004 01:41 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 11:34 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration