LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-31-2002, 10:00 AM   #1
GT-GEO
LQ Newbie
 
Registered: Nov 2001
Location: Rep. Georgia
Distribution: RedHat
Posts: 11

Rep: Reputation: 0
whati is your opinion about my firewall rules?


i have not nat. all ip-s are real in my network.

#MODULES
/sbin/modprobe ipt_LOG
/sbin/modprobe ipt_REJECT
#cleare rules
iptables -F
#INPUT-- external interface on server.
iptables -A INPUT -m limit --limit 3/minute --limit-burst 3 -j LOG --log-level DEBUG --log-prefix "IPT FORWARD packet died: "
iptables -A INPUT -p tcp ! --syn -m state --state NEW -j DROP
iptables -A INPUT -p tcp --tcp-flags SYN,ACK,FIN,RST RST -m limit --limit 1/s -j ACCEPT
iptables -A INPUT -p tcp --syn -m limit --limit 1/s -j ACCEPT
iptables -A INPUT -p icmp --icmp-type echo-request -m limit --limit 1/s -j ACCEPT
iptables -A INPUT -i eth1 -s 127.0.0.1 -j DROP
iptables -A INPUT -i eth1 -s 213.157.1.1/27 -j DROP
iptables -A INPUT -i eth1 -s 213.157.1.2 -j DROP
iptables -A INPUT -i eth1 -s 192.168.0.0/255.255.255.255 -j DROP
iptables -A INPUT -i eth1 -s 0/0 -p TCP --dport 6060 -j DROP #squid = 6060 port
iptables -A INPUT -i eth1 -s 0/0 -p TCP --dport 4040 -j DROP #socks = 4040 port
iptables -A INPUT -i eth1 -s 0/0 -p UDP --dport 6060 -j DROP
iptables -A INPUT -i eth1 -s 0/0 -p UDP --dport 4040 -j DROP
iptables -A INPUT -i eth1 -s 0/0 -p TCP --dport 22 -j DROP
iptables -A INPUT -i eth1 -s 0/0 -p TCP --dport 22 -j DROP
iptables -A INPUT -i eth1 -s 0/0 -p TCP --dport 110 -j DROP
iptables -A INPUT -i eth1 -s 0/0 -p TCP --dport 110 -j DROP
iptables -A INPUT -i eth1 -s 0/0 -p TCP --dport 1032 -j DROP
iptables -A INPUT -i eth1 -s 0/0 -p TCP --dport 1812 -j DROP
iptables -A INPUT -i eth1 -s 0/0 -p TCP --dport 1813 -j DROP
iptables -A INPUT -i eth1 -s 0/0 -p TCP --dport 3130 -j DROP
iptables -A INPUT -i eth1 -s 0/0 -p TCP --dport 3306 -j DROP
iptables -A INPUT -i eth1 -s 0/0 -p UDP --dport 3306 -j DROP
#
iptables -A FORWARD -m limit --limit 3/minute --limit-burst 3 -j LOG --log-level DEBUG --log-prefix "IPT FORWARD packet died: "
#
iptables -A INPUT -p tcp ! --syn -m state --state NEW -j DROP
#OUT--TCP
iptables -A FORWARD -o eth1 -s 213.157.1.1/27 -p TCP --dport 110 -d pop.mail.yahoo.com -j ACCEPT
iptables -A FORWARD -o eth1 -s 213.157.1.1/27 -p TCP --dport 110 -d mail.online.ge -j ACCEPT
#INPUT--TCP
iptables -A FORWARD -i eth1 -s pop.mail.yahoo.com -p TCP --sport 110 -d 213.157.1.1/27 -j ACCEPT
iptables -A FORWARD -i eth1 -s mail.online.ge -p TCP --sport 25 -d 213.157.1.1/27 -j ACCEPT
#OUT--ICMP
iptables -A FORWARD -o eth1 -s 213.157.1.1/27 -p ICMP --icmp-type 8 -j ACCEPT
#INPUT--ICMP
iptables -A FORWARD -i eth1 -d 213.157.1.1/27 -p ICMP --icmp-type 0 -j ACCEPT
iptables -A FORWARD -i eth1 -s 0/0 -p ICMP --icmp-type 8 -j DROP
iptables -A FORWARD -i eth1 -d 213.157.1.1/27 -p ICMP --icmp-type 3 -j ACCEPT
iptables -A FORWARD -i eth1 -d 213.157.1.1/27 -p ICMP --icmp-type 5 -j ACCEPT
iptables -A FORWARD -i eth1 -d 213.157.1.1/27 -p ICMP --icmp-type 11 -j ACCEPT
#
iptables -A FORWARD -p tcp --tcp-flags SYN,ACK,FIN,RST RST -m limit --limit 1/s -j ACCEPT
#
iptables -A FORWARD -p tcp --syn -m limit --limit 1/s -j ACCEPT
#
iptables -A FORWARD -p icmp --icmp-type echo-request -m limit --limit 1/s -j ACCEPT
#DENY ALL
iptables -A FORWARD -i eth1 -j DROP
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Resetting ALL Firewall rules RemusX2 Linux - Software 1 02-28-2005 07:18 AM
Firewall Rules studpenguin Linux - Security 0 07-01-2004 03:14 AM
help with firewall rules please deuce868 Linux - Security 1 06-14-2004 03:18 PM
help building my firewall rules rhawi Linux - Security 19 05-16-2004 09:29 PM
Dynamic Firewall Rules DavidPhillips Linux - General 2 12-06-2001 06:41 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:31 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration