Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #174663
| From | deloptes <deloptes@gmail.com> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: iptables question |
| Date | 2016-11-13 20:50 +0100 |
| Message-ID | <sD8WS-4H9-3@gated-at.bofh.it> (permalink) |
| References | (1 earlier) <sCP7P-8pY-13@gated-at.bofh.it> <sCQQn-18E-5@gated-at.bofh.it> <sD1iG-82r-33@gated-at.bofh.it> <sD4zU-1Tt-25@gated-at.bofh.it> <sD6im-2Rf-29@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Pascal Hambourg wrote: > Le 13/11/2016 à 16:05, deloptes a écrit : >> >> These are the rules - a friend created this like 10y ago. I added few >> rules to forward ports from outside to the intranet and to be able to >> handle VPN. >> You can ignore 192.168.60.1 on eth2 - not used. > > IMO, this ruleset is totally insane. > Haha, yes for me it is also hard to understand it all ... but as I said in the past 10y it did a good work. > However, after clearing out all irrelevant rules, I see nothing in what > is left which may block connections from 192.168.40.0/24 on eth1 to > anywhere through the firewall : > > *nat > :PREROUTING ACCEPT [26000:2533530] > :POSTROUTING ACCEPT [87:4966] > :OUTPUT ACCEPT [28:2038] > -A POSTROUTING -s 192.168.40.0/24 -o eth0 -j SNAT --to-source 10.0.0.1 > COMMIT > *filter > :INPUT DROP [0:0] > :FORWARD DROP [0:0] > :OUTPUT DROP [0:0] > :ifilter - [0:0] > :ofilter - [0:0] > -A INPUT -j ifilter > -A FORWARD -j ifilter > -A FORWARD -j ofilter > -A OUTPUT -j ofilter > -A ifilter -m state --state RELATED,ESTABLISHED -j ACCEPT > -A ifilter -i eth1 -m state --state NEW -j ACCEPT > > What happens exactly when your try to connect ? What is the command, > what is the reply ? Did you make a packet capture on eth0 ? > I do ssh user@10...6 and nothing happens - connection time out after ~1min > Did you check the routing table on the firewall and the targets ? Do > they have a route to all the 10.0.0.0/24 range ? > the one I posted is on the firewall - firewall is the one I am trying to modify. I am not sure that I have a rule to all the 10.0.0.0/24 range, but even if I replace 10.0.0.1/32 with 10.0.0.0/24 it does not work >> Another important information perhaps is that the modem is configured to >> have a DMZ with 10.0.0.1. > > I don't think this is relevant. The modem is not involved. > The modem is a wireless modem so the cable goes to the firewall 10..1 and via the wlan I have 10..6 etc. So IMO it is involved, but I do not have root on it - I have only the admin iface and there I see firewall is active and setup in normal mode (you have easy and hard - translated from the local language) >> Devices 10.0.0.6 and 10.0.0.7 which I want to connect from 192.... do not >> have any firewalls - they are mobile phones. >> >> I will really appreciate your help - perhaps reviewing the rules and >> suggesting improvements as well. > > This ruleset does not need improvements but a total rewrite. Yes I was thinking the same, I'll put it on the TODO. I even tried once with fw builder - it couldn't even import properly, because import and export produced not working firewall. IT is a bit complicated. However I think the ruleset is not that bad as testing from outside shows the network 192.168... is well protected thanks regards
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
iptables question deloptes <deloptes@gmail.com> - 2016-11-12 22:20 +0100
Re: iptables question Joe <joe@jretrading.com> - 2016-11-12 23:40 +0100
Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-13 01:30 +0100
Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 10:50 +0100
Re: iptables question Michael Milliman <michael.e.milliman@gmail.com> - 2016-11-13 12:40 +0100
Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-13 16:10 +0100
Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 18:00 +0100
Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-13 20:50 +0100
Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 21:20 +0100
Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-13 21:50 +0100
Re: iptables question Henning <henning@itcfollmann.com> - 2016-11-13 22:50 +0100
Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 23:30 +0100
Re: iptables question Henning <henning@itcfollmann.com> - 2016-11-14 00:30 +0100
Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-14 00:50 +0100
Re: iptables question Henning Follmann <hfollmann@itcfollmann.com> - 2016-11-14 13:10 +0100
Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-14 20:20 +0100
Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 23:30 +0100
Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-14 01:00 +0100
Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-14 23:10 +0100
Re: iptables question Igor Cicimov <icicimov@gmail.com> - 2016-11-14 03:10 +0100
Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-14 08:20 +0100
Re: iptables question deloptes <deloptes@gmail.com> - 2016-11-14 09:10 +0100
Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 10:40 +0100
Re: iptables question Joe <joe@jretrading.com> - 2016-11-13 11:10 +0100
Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 11:40 +0100
Re: iptables question Joe <joe@jretrading.com> - 2016-11-13 13:40 +0100
Re: iptables question Pascal Hambourg <pascal@plouf.fr.eu.org> - 2016-11-13 15:00 +0100
Re: iptables question Igor Cicimov <icicimov@gmail.com> - 2016-11-14 03:00 +0100
csiph-web