Page 2 of 2 FirstFirst 12
Results 11 to 13 of 13

Thread: IPTables configuration questions

  1. #11
    Join Date
    May 2010
    Beans
    462
    Distro
    Ubuntu Development Release

    Re: IPTables configuration questions

    Actually i still feel that your iptables shall by default shall drop all connections from input, forward and output for security reasons. Then you start to allow by port and protocol. Anyway it is all yours.

  2. #12
    Join Date
    Sep 2007
    Location
    Oklahoma, USA
    Beans
    2,224
    Distro
    Xubuntu 14.04 Trusty Tahr

    Re: IPTables configuration questions

    For the LAN traffic, I think these rules should work:
    Code:
    -A FORWARD -s 10.1.10.0/24 -d 10.1.10.0/24 -j ACCEPT
    -A FORWARD -s 10.1.10.13/32 -j ACCEPT
    This should allow unlimited traffic around the LAN, but only the single IP of 10.1.10.13 would be able to transmit anything outside the LAN. Of course you would still need the RELATED,ESTABLISHED rule ahead of them, to accept responses to packets that 10.1.10.13 sent out. If you wanted to restrict that IP to only a single port or a range of ports, you could expand its rule to do so, and if you wanted to allow a different specific IP to do the same, you could add a rule for it that differed only in the final octet of the source address. Obviously, you would change these IPs to those actually involved, and the network would have to be using static IPs rather than DHCP assignment for the ACCEPT rules to remain consistent.

    Just keep in mind that the rules are visited in strict top-to-bottom sequence, so once a packet satisfies a rule that takes it to either ACCEPT or DROP/REJECT no additional rules will see it. A jump to LOG always returns after logging the data, though, and any user-defined chain that does not have an unconditional jump as its last rule will return to the chain that called it. In other words, each rule is like a subroutine in a program.
    --
    Jim Kyle in Oklahoma, USA
    Linux Counter #259718
    Howto mark thread: https://wiki.ubuntu.com/UnansweredPo.../SolvedThreads

  3. #13
    Join Date
    May 2012
    Beans
    72

    Re: IPTables configuration questions

    Thank you for all of your help Jim. I'll mark this thread solved, as I think I finally get it.

Page 2 of 2 FirstFirst 12

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •