LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 05-11-2018, 06:45 PM   #1
wsdnd
LQ Newbie
 
Registered: May 2018
Posts: 1

Rep: Reputation: Disabled
IP Tables web editor Questions


Hello,

I am in need of a solution for an ongoing issue I have.

This issue is that to ensure network security, I have blocked all IPs in iptables, adding rules for only select IPs. BTW, I am using CentOS.

I have a server that needs to be accessed by clients, some of these clients have dynamic IPs, so in order to allow them to see my server, I have to manually add them in iptables.

This has become a heartache lately due to too many clients.

I have been searching for a solution that I can implement in which clients can edit there own IP without much action from me. It needs to be a solution that clients can only edit their one iptables rule, not able to edit all or any rule. Would need to have different user login accounts.

Preferably in PHP, but if any of you know of a solution using a different language I am open to any suggestions.

Regards.

Thank you for in advance.
 
Old 05-11-2018, 08:04 PM   #2
frankbell
LQ Guru
 
Registered: Jan 2006
Location: Virginia, USA
Distribution: Slackware, Ubuntu MATE, Mageia, and whatever VMs I happen to be playing with
Posts: 19,342
Blog Entries: 28

Rep: Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145Reputation: 6145
Do your users need access to the entire machine (I'm guessing no) or only to certain files on the machine?
 
Old 05-11-2018, 09:31 PM   #3
AwesomeMachine
LQ Guru
 
Registered: Jan 2005
Location: USA and Italy
Distribution: Debian testing/sid; OpenSuSE; Fedora; Mint
Posts: 5,524

Rep: Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015Reputation: 1015
That sounds pretty tough to do with iptables. Maybe you could allow IP blocks. Usually dynamic IPs are within a certain block an ISP has.
 
Old 05-12-2018, 01:59 AM   #4
Turbocapitalist
LQ Guru
 
Registered: Apr 2005
Distribution: Linux Mint, Devuan, OpenBSD
Posts: 7,328
Blog Entries: 3

Rep: Reputation: 3726Reputation: 3726Reputation: 3726Reputation: 3726Reputation: 3726Reputation: 3726Reputation: 3726Reputation: 3726Reputation: 3726Reputation: 3726Reputation: 3726
It'd be easy enough to write something like that. It'd also be easy enough to make big mistakes. You'll really have to be very sure about input validation. There's also little that can be done to prevent them from then adding aribitrary addresses.

One way is to apply your basic set of rules and have a separate chain for the dynamic addresses which might even point to additional chains one per customer.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: W3m: Simple Text-Based Web Browser Support for SSL Connetions, Tables, and More LXer Syndicated Linux News 0 04-19-2012 09:51 PM
Questions about the console keyboard driver / translation tables Bill Cosby Programming 0 03-10-2012 03:38 PM
manipulating ascii data tables questions will.flanagan Linux - Newbie 8 04-17-2009 09:36 PM
Hash Tables - Newb to These, simple questions AquamaN Programming 4 12-12-2005 09:23 PM
web editor ahjamm Linux - Software 8 10-02-2003 12:31 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 04:13 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration