LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-08-2004, 09:27 AM   #1
moochoo59
LQ Newbie
 
Registered: Jan 2004
Posts: 1

Rep: Reputation: 0
Question Poking Holes in Linux Firewall, Kernel 2.2


Greetings, thanks for your time. I must apologise at the outset for my distinct lack of knowledge pertaining to non-Microsoft products.

I am running Linux Kernel 2.2, and hence am using IPTABLES for my firewall (and masquerading) needs. I recently have been required to open up a small hole in the firewall, specifically incoming TCP ports 6881-6999. (Some intrepid downloaders may recognise those as the default Bittorrent ports.) Being hopelessly clueless with *nix, I searched, finding only an ipTABLES command that would apparently solve said problem:

Code:
iptables -t nat -I PREROUTING -p tcp --dport 6881:6889 -j DNAT --to-destination <host>
... where <host> is the private or internal IP actually running the BT client.

My question is thus: what would the equivalent command be for 2.2, ie IPCHAINS?
I realise that there would be no 'direct' translation, but possibly something simple?
Failing that, would anyone be able to assist me in finding an easier way to poke a hole in the firewall with MASQ and IPCHAINS?

For those who are interested, my current firewall is based on the model at: en.tldp.org/HOWTO/IP-Masquerade-HOWTO/firewall-examples.html#RC.FIREWALL-2.2.X

Any and all assistance is greatly appreciated.
 
Old 01-08-2004, 04:21 PM   #2
jailbait
LQ Guru
 
Registered: Feb 2003
Location: Virginia, USA
Distribution: Debian 12
Posts: 8,339

Rep: Reputation: 550Reputation: 550Reputation: 550Reputation: 550Reputation: 550Reputation: 550
"My question is thus: what would the equivalent command be for 2.2, ie IPCHAINS?
I realise that there would be no 'direct' translation, but possibly something simple?"

The best way to translate the prototype you have found to your own needs would be to read:
man iptables

http://www.linuxguruz.com/iptables/h...niptables.html

You should have man ipchains on your Linux system. If you do not then:

http://www.rt.com/man/ipchains.8.html

Using the two man pages you should be able to map the prototype iptables command to your own ipchains command.

___________________________________
Be prepared. Create a LifeBoat CD.
http://users.rcn.com/srstites/LifeBo...home.page.html

Steve Stites
 
Old 04-13-2004, 08:07 PM   #3
chucky88
LQ Newbie
 
Registered: Apr 2004
Posts: 2

Rep: Reputation: 0
moochoo59, did you end up finding the answer you wanted?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Poking holes in my Firewall for SMB shares Mr. Slappy SUSE / openSUSE 7 06-20-2005 01:53 PM
Firewall full of holes. Proxy authentication ? fipeso Linux - Security 3 05-07-2005 03:05 AM
Punching holes through the RedHat 9 firewall fturcic Linux - Security 2 03-11-2005 01:15 AM
holes in firewall? ryedunn Linux - Security 1 10-16-2004 02:37 PM
telnet holes?? r2ii Linux - Security 9 08-11-2004 06:11 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 06:58 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration