Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #375

Re: Dropping incoming connections from a given domain

From Pascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Newsgroups comp.os.linux.networking
Subject Re: Dropping incoming connections from a given domain
Date 2011-06-17 09:08 +0200
Organization Plouf !
Message-ID <iteugi$1f6q$1@saria.nerim.net> (permalink)
References <itdltg$6dr$1@news.albasani.net> <itdos3$2ufn$1@saria.nerim.net> <ite65q$2la$1@news.albasani.net>

Show all headers | View raw


S.K.R. de Jong a écrit :
> 
> 	In that case, can it be done on the basis of matching IP 
> addresses? For instance, would it be possible to get iptables to discard 
> packets from, say, 192.168.xxx.yyy, where xxx and yyy are integers 
> between 0 and 255?

Of course. This is basic.
You can match a prefix :

iptables -A INPUT -s 192.168.0.0/16 -j DROP

or an arbitrary range :

iptables -A INPUT -m iprange --src-range 192.168.0.0-192.168.255.255 \
  -j DROP

Back to comp.os.linux.networking | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

Dropping incoming connections from a given domain "S.K.R. de Jong" <SKRdJ@nowhere.net> - 2011-06-16 19:35 +0000
  Re: Dropping incoming connections from a given domain Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2011-06-16 22:25 +0200
    Re: Dropping incoming connections from a given domain Rick Jones <rick.jones2@hp.com> - 2011-06-16 20:29 +0000
    Re: Dropping incoming connections from a given domain "S.K.R. de Jong" <SKRdJ@nowhere.net> - 2011-06-17 00:12 +0000
      Re: Dropping incoming connections from a given domain Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2011-06-17 09:08 +0200

csiph-web