Hi, I wonder if one of the knowledgeable bods could just check my iptables.rules file to confirm that this would not lock me out completely if I flushed iptables?
I edited it manually to change the Default Input rule to ACCEPT and add the -A INPUT -i eth0 -j DROP rule to drop all traffic that does not match the rules above it.Code:# Generated by iptables-save v1.3.8 on Wed Jun 30 09:27:01 2010 *mangle :PREROUTING ACCEPT [693580:80935179] :INPUT ACCEPT [693534:80929158] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [600675:160083835] :POSTROUTING ACCEPT [600675:160083835] COMMIT # Completed on Wed Jun 30 09:27:01 2010 # Generated by iptables-save v1.3.8 on Wed Jun 30 09:27:01 2010 *nat :PREROUTING ACCEPT [109155:11254124] :POSTROUTING ACCEPT [2862:209097] :OUTPUT ACCEPT [2862:209097] COMMIT # Completed on Wed Jun 30 09:27:01 2010 # Generated by iptables-save v1.3.8 on Wed Jun 30 09:27:01 2010 *filter :INPUT ACCEPT [104497:11005055] :FORWARD ACCEPT [0:0] :OUTPUT ACCEPT [600677:160084088] -A INPUT -i tun0 -j ACCEPT -A INPUT -i lo -j ACCEPT -A INPUT -i eth0 -p tcp -m tcp --dport 80 -j ACCEPT -A INPUT -i eth0 -p tcp -m tcp --dport 443 -j ACCEPT -A INPUT -i eth0 -m state --state ESTABLISHED -j ACCEPT -A INPUT -i eth0 -m state --state RELATED -j ACCEPT -A INPUT -i eth0 -j DROP COMMIT # Completed on Wed Jun 30 09:27:01 2010
Is that correct?
Bookmarks