Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.networking > #371 > unrolled thread

Dropping incoming connections from a given domain

Started by"S.K.R. de Jong" <SKRdJ@nowhere.net>
First post2011-06-16 19:35 +0000
Last post2011-06-17 09:08 +0200
Articles 5 — 3 participants

Back to article view | Back to comp.os.linux.networking


Contents

  Dropping incoming connections from a given domain "S.K.R. de Jong" <SKRdJ@nowhere.net> - 2011-06-16 19:35 +0000
    Re: Dropping incoming connections from a given domain Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2011-06-16 22:25 +0200
      Re: Dropping incoming connections from a given domain Rick Jones <rick.jones2@hp.com> - 2011-06-16 20:29 +0000
      Re: Dropping incoming connections from a given domain "S.K.R. de Jong" <SKRdJ@nowhere.net> - 2011-06-17 00:12 +0000
        Re: Dropping incoming connections from a given domain Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> - 2011-06-17 09:08 +0200

#371 — Dropping incoming connections from a given domain

From"S.K.R. de Jong" <SKRdJ@nowhere.net>
Date2011-06-16 19:35 +0000
SubjectDropping incoming connections from a given domain
Message-ID<itdltg$6dr$1@news.albasani.net>
	I am looking for an iptables incantation that would allow all 
connection attempts from IP addresses in a given domain. Is this possible?

[toc] | [next] | [standalone]


#372

FromPascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Date2011-06-16 22:25 +0200
Message-ID<itdos3$2ufn$1@saria.nerim.net>
In reply to#371
Hello,

S.K.R. de Jong a écrit :
> 	I am looking for an iptables incantation that would allow all 
> connection attempts from IP addresses in a given domain. Is this possible?

What do you mean by "IP addresses in a given domain" ?

If you mean the reverse DNS being in a given domain, not easily.
Iptables rules are run by the kernel and the kernel knows nothing about
DNS. You would need to QUEUE packets and do the reverse DNS resolution
in userland.

[toc] | [prev] | [next] | [standalone]


#373

FromRick Jones <rick.jones2@hp.com>
Date2011-06-16 20:29 +0000
Message-ID<itdp43$k9b$2@usenet01.boi.hp.com>
In reply to#372
Pascal Hambourg <boite-a-spam@plouf.fr.eu.org> wrote:
> S.K.R. de Jong a écrit :

> >       I am looking for an iptables incantation that would allow
> > all connection attempts from IP addresses in a given domain. Is
> > this possible?

> What do you mean by "IP addresses in a given domain" ?

> If you mean the reverse DNS being in a given domain, not easily.
> Iptables rules are run by the kernel and the kernel knows nothing about
> DNS. You would need to QUEUE packets and do the reverse DNS resolution
> in userland.

And if the conversations in one of the DNS lists are indicative of the
future, it may be increasingly rare that there are PTR records in the
DNS in the first place - there seems to be resistance to adding them
for IPv6.

rick jones
-- 
The computing industry isn't as much a game of "Follow The Leader" as
it is one of "Ring Around the Rosy" or perhaps "Duck Duck Goose." 
                                                    - Rick Jones
these opinions are mine, all mine; HP might not want them anyway... :)
feel free to post, OR email to rick.jones2 in hp.com but NOT BOTH...

[toc] | [prev] | [next] | [standalone]


#374

From"S.K.R. de Jong" <SKRdJ@nowhere.net>
Date2011-06-17 00:12 +0000
Message-ID<ite65q$2la$1@news.albasani.net>
In reply to#372
On Thu, 16 Jun 2011 22:25:38 +0200, Pascal Hambourg wrote:

> Hello,
> 
> S.K.R. de Jong a écrit :
>> 	I am looking for an iptables incantation that would allow all
>> connection attempts from IP addresses in a given domain. Is this
>> possible?
> 
> What do you mean by "IP addresses in a given domain" ?
> 
> If you mean the reverse DNS being in a given domain, not easily.
> Iptables rules are run by the kernel and the kernel knows nothing about
> DNS. You would need to QUEUE packets and do the reverse DNS resolution
> in userland.

	In that case, can it be done on the basis of matching IP 
addresses? For instance, would it be possible to get iptables to discard 
packets from, say, 192.168.xxx.yyy, where xxx and yyy are integers 
between 0 and 255?

[toc] | [prev] | [next] | [standalone]


#375

FromPascal Hambourg <boite-a-spam@plouf.fr.eu.org>
Date2011-06-17 09:08 +0200
Message-ID<iteugi$1f6q$1@saria.nerim.net>
In reply to#374
S.K.R. de Jong a écrit :
> 
> 	In that case, can it be done on the basis of matching IP 
> addresses? For instance, would it be possible to get iptables to discard 
> packets from, say, 192.168.xxx.yyy, where xxx and yyy are integers 
> between 0 and 255?

Of course. This is basic.
You can match a prefix :

iptables -A INPUT -s 192.168.0.0/16 -j DROP

or an arbitrary range :

iptables -A INPUT -m iprange --src-range 192.168.0.0-192.168.255.255 \
  -j DROP

[toc] | [prev] | [standalone]


Back to top | Article view | comp.os.linux.networking


csiph-web