Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #174659

Re: iptables question

From Pascal Hambourg <pascal@plouf.fr.eu.org>
Newsgroups linux.debian.user
Subject Re: iptables question
Date 2016-11-13 18:00 +0100
Message-ID <sD6im-2Rf-29@gated-at.bofh.it> (permalink)
References <sCNSp-7BL-15@gated-at.bofh.it> <sCP7P-8pY-13@gated-at.bofh.it> <sCQQn-18E-5@gated-at.bofh.it> <sD1iG-82r-33@gated-at.bofh.it> <sD4zU-1Tt-25@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Le 13/11/2016 à 16:05, deloptes a écrit :
>
> These are the rules - a friend created this like 10y ago. I added few rules
> to forward ports from outside to the intranet and to be able to handle VPN.
> You can ignore  192.168.60.1 on eth2 - not used.

IMO, this ruleset is totally insane.

However, after clearing out all irrelevant rules, I see nothing in what 
is left which may block connections from 192.168.40.0/24 on eth1 to 
anywhere through the firewall :

*nat
:PREROUTING ACCEPT [26000:2533530]
:POSTROUTING ACCEPT [87:4966]
:OUTPUT ACCEPT [28:2038]
-A POSTROUTING -s 192.168.40.0/24 -o eth0 -j SNAT --to-source 10.0.0.1
COMMIT
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT DROP [0:0]
:ifilter - [0:0]
:ofilter - [0:0]
-A INPUT -j ifilter
-A FORWARD -j ifilter
-A FORWARD -j ofilter
-A OUTPUT -j ofilter
-A ifilter -m state --state RELATED,ESTABLISHED -j ACCEPT
-A ifilter -i eth1 -m state --state NEW -j ACCEPT

What happens exactly when your try to connect ? What is the command, 
what is the reply ? Did you make a packet capture on eth0 ?

Did you check the routing table on the firewall and the targets ? Do 
they have a route to all the 10.0.0.0/24 range ?

> Another important information perhaps is that the modem is configured to
> have a DMZ with 10.0.0.1.

I don't think this is relevant. The modem is not involved.

> Devices 10.0.0.6 and 10.0.0.7 which I want to connect from 192.... do not
> have any firewalls - they are mobile phones.
>
> I will really appreciate your help - perhaps reviewing the rules and
> suggesting improvements as well.

This ruleset does not need improvements but a total rewrite.

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

iptables question deloptes <deloptes@gmail.com> - 2016-11-12 22:20 +0100
  Re: iptables question Joe <joe@jretrading.com> - 2016-11-12 23:40 +0100
    Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-13 01:30 +0100
      Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 10:50 +0100
      Re: iptables question Michael Milliman <michael.e.milliman@gmail.com> - 2016-11-13 12:40 +0100
        Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-13 16:10 +0100
          Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 18:00 +0100
            Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-13 20:50 +0100
              Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 21:20 +0100
                Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-13 21:50 +0100
                Re: iptables question Henning <henning@itcfollmann.com> - 2016-11-13 22:50 +0100
                Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 23:30 +0100
                Re: iptables question Henning <henning@itcfollmann.com> - 2016-11-14 00:30 +0100
                Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-14 00:50 +0100
                Re: iptables question Henning Follmann <hfollmann@itcfollmann.com> - 2016-11-14 13:10 +0100
                Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-14 20:20 +0100
                Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 23:30 +0100
                Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-14 01:00 +0100
                Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-14 23:10 +0100
      Re: iptables question Igor Cicimov <icicimov@gmail.com> - 2016-11-14 03:10 +0100
        Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-14 08:20 +0100
          Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-14 09:10 +0100
    Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 10:40 +0100
      Re: iptables question Joe <joe@jretrading.com> - 2016-11-13 11:10 +0100
        Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 11:40 +0100
          Re: iptables question Joe <joe@jretrading.com> - 2016-11-13 13:40 +0100
            Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 15:00 +0100
              Re: iptables question Igor Cicimov <icicimov@gmail.com> - 2016-11-14 03:00 +0100

csiph-web