<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
					xmlns:content="http://purl.org/rss/1.0/modules/content/"
					xmlns:wfw="http://wellformedweb.org/CommentAPI/"
					xmlns:atom="http://www.w3.org/2005/Atom"
				  >
<channel>
<atom:link rel="self"  type="application/rss+xml"  href="http://rulinux.net/rss_from_sect_4_subsect_8_thread_1179"  />
<title>rulinux.net - Форум - Security - iptables на домашнем компьютере</title>
<link>http://rulinux.net/</link>
<description><![CDATA[Портал о GNU/Linux и не только]]></description>
<image><title>rulinux.net - Форум - Security - iptables на домашнем компьютере</title>
<link>http://rulinux.net/</link>
<url>http://rulinux.net/rss_icon.png</url>
</image>
<item>
<title>Re: iptables на домашнем компьютере</title>
<link>https://rulinux.net/message.php?newsid=1179&amp;page=1#8159</link>
<guid>https://rulinux.net/message.php?newsid=1179&amp;page=1#8159</guid>
<pubDate>Thu, 19 May 2011 19:35:05 +0400</pubDate>
<description><![CDATA[<p>Извращенцы.</p><p>:INPUT DROP [0:0] :FORWARD DROP [0:0] :OUTPUT ACCEPT [0:0] -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT  -A INPUT -i lo -j ACCEPT </p>]]></description>
</item>
<item>
<title>Re:iptables на домашнем компьютере</title>
<link>https://rulinux.net/message.php?newsid=1179&amp;page=1#8158</link>
<guid>https://rulinux.net/message.php?newsid=1179&amp;page=1#8158</guid>
<pubDate>Sat, 16 May 2009 20:26:09 +0400</pubDate>
<description><![CDATA[<p style="font-style:italic">&gt; % cat /etc/hosts.deny</p><p>не все серверные проги оглядываются на tcp-wrappers, даже по дефолту</p>]]></description>
</item>
<item>
<title>Re:iptables на домашнем компьютере</title>
<link>https://rulinux.net/message.php?newsid=1179&amp;page=1#8157</link>
<guid>https://rulinux.net/message.php?newsid=1179&amp;page=1#8157</guid>
<pubDate>Sat, 16 May 2009 20:24:19 +0400</pubDate>
<description><![CDATA[<p>*упорство кончилось)*</p>]]></description>
</item>
<item>
<title>Re:iptables на домашнем компьютере</title>
<link>https://rulinux.net/message.php?newsid=1179&amp;page=1#8156</link>
<guid>https://rulinux.net/message.php?newsid=1179&amp;page=1#8156</guid>
<pubDate>Sat, 16 May 2009 20:23:26 +0400</pubDate>
<description><![CDATA[<p>-P INPUT DROP
-P FORWARD DROP
-P OUTPUT ACCEPT
-N allowed
-N bad_tcp
-N icmp_pack
-N tcp_pack
-N udp_pack
-A INPUT -m state &#8211;state INVALID -j LOG &#8211;log-prefix "INVALID temp log:" &#8211;log-level 7 
-A INPUT -p tcp -j bad_tcp 
-A INPUT -s 127.0.0.1/32 -i lo -j ACCEPT 
-A INPUT -s 127.0.0.1/32 ! -i lo -j DROP 
-A INPUT -i eth0 -m state &#8211;state RELATED,ESTABLISHED -j ACCEPT 
-A INPUT -i eth1 -m state &#8211;state RELATED,ESTABLISHED -j ACCEPT 
-A INPUT -i ppp0 -m state &#8211;state RELATED,ESTABLISHED -j ACCEPT 
-A INPUT -i eth0 -p tcp -j tcp_pack 
-A INPUT -i eth1 -p tcp -j tcp_pack 
-A INPUT -i eth0 -p udp -j udp_pack 
-A INPUT -i eth1 -p udp -j udp_pack 
-A INPUT -i eth0 -p icmp -j icmp_pack 
-A INPUT -i eth1 -p icmp -j icmp_pack 
-A INPUT -d 224.0.0.0/8 -i eth0 -j DROP 
-A INPUT -d 224.0.0.0/8 -i eth1 -j DROP 
-A INPUT -m limit &#8211;limit 3/min &#8211;limit-burst 3 -j LOG &#8211;log-prefix "IPT INPUT packets died:" &#8211;log-level 7 
-A allowed -p tcp -m tcp &#8211;tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT 
-A allowed -p tcp -m state &#8211;state RELATED,ESTABLISHED -j ACCEPT 
-A allowed -p tcp -j DROP 
-A bad_tcp -p tcp -m tcp &#8211;tcp-flags SYN,ACK SYN,ACK -m state &#8211;state NEW -j REJECT &#8211;reject-with tcp-reset 
-A bad_tcp -p tcp -m tcp &#8211;dport 6000:6063 &#8211;tcp-flags FIN,SYN,RST,ACK SYN -j DROP 
-A bad_tcp -p tcp -m tcp &#8211;dport 113 -j DROP 
-A bad_tcp -p tcp -m tcp ! &#8211;tcp-flags FIN,SYN,RST,ACK SYN -m state &#8211;state NEW -j LOG &#8211;log-prefix "New not SYN:" &#8211;log-level 7 
-A bad_tcp -p tcp -m tcp ! &#8211;tcp-flags FIN,SYN,RST,ACK SYN -m state &#8211;state NEW -j DROP 
-A icmp_pack -p icmp -j LOG &#8211;log-prefix "ICMP temp log:" &#8211;log-level 7 
-A icmp_pack -p icmp -f -j DROP 
-A icmp_pack -p icmp -m icmp &#8211;icmp-type 8 -j ACCEPT 
-A icmp_pack -p icmp -m icmp &#8211;icmp-type 11 -j ACCEPT 
-A tcp_pack -i eth0 -p tcp -m tcp &#8211;dport 29317 -j allowed 
-A tcp_pack -i eth0 -p tcp -m tcp &#8211;dport 10100 -j allowed 
-A tcp_pack -i eth1 -p tcp -m tcp &#8211;dport 35572 -j allowed 
-A tcp_pack -i eth1 -p tcp -m tcp &#8211;dport 36562 -j allowed 
-A tcp_pack -p tcp -m tcp &#8211;dport 21 -j allowed 
-A udp_pack -p udp -m udp &#8211;dport 135:138 -j DROP 
-A udp_pack -p udp -m udp &#8211;dport 67:68 -j DROP 
-A udp_pack -p udp -m udp &#8211;dport 1947 -j DROP 
-A udp_pack -p udp -m udp &#8211;dport 6646 -j DROP 
-A udp_pack -p udp -m udp &#8211;dport 9999 -j DROP 
-A udp_pack -i eth0 -p udp -m udp &#8211;dport 10100 -j ACCEPT 
-A udp_pack -i eth1 -p udp -m udp &#8211;dport 35572 -j ACCEPT 
</p>]]></description>
</item>
<item>
<title>Re:iptables на домашнем компьютере</title>
<link>https://rulinux.net/message.php?newsid=1179&amp;page=1#8155</link>
<guid>https://rulinux.net/message.php?newsid=1179&amp;page=1#8155</guid>
<pubDate>Sat, 16 May 2009 20:22:43 +0400</pubDate>
<description><![CDATA[<p>-P INPUT DROP
-P FORWARD DROP
-P OUTPUT ACCEPT
-N allowed
-N bad_tcp
-N icmp_pack
-N tcp_pack
-N udp_pack
-A INPUT -m state &#8211;state INVALID -j LOG &#8211;log-prefix "INVALID temp log:" &#8211;log-level 7 
-A INPUT -p tcp -j bad_tcp 
-A INPUT -s 127.0.0.1/32 -i lo -j ACCEPT 
-A INPUT -s 127.0.0.1/32 ! -i lo -j DROP 
-A INPUT -i eth0 -m state &#8211;state RELATED,ESTABLISHED -j ACCEPT 
-A INPUT -i eth1 -m state &#8211;state RELATED,ESTABLISHED -j ACCEPT 
-A INPUT -i ppp0 -m state &#8211;state RELATED,ESTABLISHED -j ACCEPT 
-A INPUT -i eth0 -p tcp -j tcp_pack 
-A INPUT -i eth1 -p tcp -j tcp_pack 
-A INPUT -i eth0 -p udp -j udp_pack 
-A INPUT -i eth1 -p udp -j udp_pack 
-A INPUT -i eth0 -p icmp -j icmp_pack 
-A INPUT -i eth1 -p icmp -j icmp_pack 
-A INPUT -d 224.0.0.0/8 -i eth0 -j DROP 
-A INPUT -d 224.0.0.0/8 -i eth1 -j DROP 
-A INPUT -m limit &#8211;limit 3/min &#8211;limit-burst 3 -j LOG &#8211;log-prefix "IPT INPUT packets died:" &#8211;log-level 7 
-A allowed -p tcp -m tcp &#8211;tcp-flags FIN,SYN,RST,ACK SYN -j ACCEPT 
-A allowed -p tcp -m state &#8211;state RELATED,ESTABLISHED -j ACCEPT 
-A allowed -p tcp -j DROP 
-A bad_tcp -p tcp -m tcp &#8211;tcp-flags SYN,ACK SYN,ACK -m state &#8211;state NEW -j REJECT &#8211;reject-with tcp-reset 
-A bad_tcp -p tcp -m tcp &#8211;dport 6000:6063 &#8211;tcp-flags FIN,SYN,RST,ACK SYN -j DROP 
-A bad_tcp -p tcp -m tcp &#8211;dport 113 -j DROP 
-A bad_tcp -p tcp -m tcp ! &#8211;tcp-flags FIN,SYN,RST,ACK SYN -m state &#8211;state NEW -j LOG &#8211;log-prefix "New not SYN:" &#8211;log-level 7 
-A bad_tcp -p tcp -m tcp ! &#8211;tcp-flags FIN,SYN,RST,ACK SYN -m state &#8211;state NEW -j DROP 
-A icmp_pack -p icmp -j LOG &#8211;log-prefix "ICMP temp log:" &#8211;log-level 7 
-A icmp_pack -p icmp -f -j DROP 
-A icmp_pack -p icmp -m icmp &#8211;icmp-type 8 -j ACCEPT 
-A icmp_pack -p icmp -m icmp &#8211;icmp-type 11 -j ACCEPT 
-A tcp_pack -i eth0 -p tcp -m tcp &#8211;dport 29317 -j allowed 
-A tcp_pack -i eth0 -p tcp -m tcp &#8211;dport 10100 -j allowed 
-A tcp_pack -i eth1 -p tcp -m tcp &#8211;dport 35572 -j allowed 
-A tcp_pack -i eth1 -p tcp -m tcp &#8211;dport 36562 -j allowed 
-A tcp_pack -p tcp -m tcp &#8211;dport 21 -j allowed 
-A udp_pack -p udp -m udp &#8211;dport 135:138 -j DROP 
-A udp_pack -p udp -m udp &#8211;dport 67:68 -j DROP 
-A udp_pack -p udp -m udp &#8211;dport 1947 -j DROP 
-A udp_pack -p udp -m udp &#8211;dport 6646 -j DROP 
-A udp_pack -p udp -m udp &#8211;dport 9999 -j DROP 
-A udp_pack -i eth0 -p udp -m udp &#8211;dport 10100 -j ACCEPT 
-A udp_pack -i eth1 -p udp -m udp &#8211;dport 35572 -j ACCEPT </p><p>*drop в конце, чтобы логи были чуточку почише</p>]]></description>
</item>
<item>
<title>Re:iptables на домашнем компьютере</title>
<link>https://rulinux.net/message.php?newsid=1179&amp;page=1#8154</link>
<guid>https://rulinux.net/message.php?newsid=1179&amp;page=1#8154</guid>
<pubDate>Thu, 07 May 2009 07:59:16 +0400</pubDate>
<description><![CDATA[<p>Мои настройки ipt на домашнем сервере:</p><p>#!/bin/sh</p><p>WAN=&#039;ppp0&#039;
LAN=&#039;eth1&#039;
LAN_NET_X200=&#039;192.168.0.0/24&#039;
LAN_NET_KVM=&#039;192.168.100.0/24&#039;
LAN_NET_ZAURUS=&#039;192.168.129.0/24&#039;</p><p>iptables -F
iptables -t nat -F</p><p># default policy
iptables -P INPUT DROP
iptables -P OUTPUT ACCEPT
iptables -P FORWARD ACCEPT</p><p># loopback
iptables -I INPUT 1 -i lo -j ACCEPT</p><p># ftp
iptables -A INPUT &#8211;protocol tcp &#8211;dport 21 -j ACCEPT</p><p># ssh
iptables -A INPUT &#8211;protocol tcp &#8211;dport 22 -j ACCEPT
# x11 forwarding
iptables -A INPUT &#8211;protocol tcp &#8211;dport 6000 -j ACCEPT</p><p># http
iptables -A INPUT &#8211;protocol tcp &#8211;dport 80 -j ACCEPT</p><p># https
iptables -A INPUT &#8211;protocol tcp &#8211;dport 443 -j ACCEPT</p><p># torrent
iptables -A INPUT &#8211;protocol tcp &#8211;dport 51413 -j ACCEPT
# webui
iptables -A INPUT &#8211;protocol tcp &#8211;dport 8112 -j ACCEPT</p><p># git
iptables -A INPUT &#8211;protocol tcp &#8211;dport 9418 -j ACCEPT</p><p># nat for x200
iptables -t nat -A POSTROUTING -s $LAN_NET_X200 -j MASQUERADE
# nat for kvm
iptables -t nat -A POSTROUTING -s $LAN_NET_KVM -j MASQUERADE
# nat for zaurus
iptables -t nat -A POSTROUTING -s $LAN_NET_ZAURUS -j MASQUERADE
# solving ppp troubles
iptables -I FORWARD -p tcp &#8211;tcp-flags SYN,RST SYN -j TCPMSS &#8211;clamp-mss-to-pmtu</p><p># icmp
iptables -A INPUT -p icmp -j ACCEPT</p><p># passing packets from esatblished and related connections
iptables -A INPUT -m state &#8211;state ESTABLISHED,RELATED -j ACCEPT
iptables -A OUTPUT -m state &#8211;state ESTABLISHED,RELATED -j ACCEPT
iptables -A FORWARD -m state &#8211;state ESTABLISHED,RELATED -j ACCEPT
</p>]]></description>
</item>
<item>
<title>Re:iptables на домашнем компьютере</title>
<link>https://rulinux.net/message.php?newsid=1179&amp;page=1#8153</link>
<guid>https://rulinux.net/message.php?newsid=1179&amp;page=1#8153</guid>
<pubDate>Fri, 17 Apr 2009 18:59:58 +0400</pubDate>
<description><![CDATA[<p>% cat /etc/hosts.deny</p><p>ALL: ALL: DENY</p>]]></description>
</item>
<item>
<title>Re:iptables на домашнем компьютере</title>
<link>https://rulinux.net/message.php?newsid=1179&amp;page=1#8152</link>
<guid>https://rulinux.net/message.php?newsid=1179&amp;page=1#8152</guid>
<pubDate>Tue, 14 Apr 2009 11:43:55 +0400</pubDate>
<description><![CDATA[<p>Я его дома не держу.</p>]]></description>
</item>
<item>
<title>Re:iptables на домашнем компьютере</title>
<link>https://rulinux.net/message.php?newsid=1179&amp;page=1#8151</link>
<guid>https://rulinux.net/message.php?newsid=1179&amp;page=1#8151</guid>
<pubDate>Tue, 14 Apr 2009 11:19:34 +0400</pubDate>
<description><![CDATA[<p>#!/bin/sh</p><p>IPTABLES=`which iptables`</p><p>$IPTABLES -F</p><p>$IPTABLES -t nat -F</p><p>$IPTABLES -P INPUT DROP</p><p>$IPTABLES -P OUTPUT ACCEPT</p><p>$IPTABLES -P FORWARD DROP</p><p>$IPTABLES -A INPUT -i lo -j ACCEPT</p><p>$IPTABLES -A INPUT -p tcp -m state &#8211;state ESTABLISHED,RELATED -j ACCEPT</p><p>$IPTABLES -A INPUT -p udp -j ACCEPT </p><p>$IPTABLES -A INPUT -p icmp -j ACCEPT
</p>]]></description>
</item>
<item>
<title>iptables на домашнем компьютере</title>
<link>https://rulinux.net/message.php?newsid=1179&amp;page=1#8150</link>
<guid>https://rulinux.net/message.php?newsid=1179&amp;page=1#8150</guid>
<pubDate>Tue, 14 Apr 2009 11:17:19 +0400</pubDate>
<description><![CDATA[<p>У меня довольно простой скрипт настройки iptables</p><p>#!/bin/sh</p><p>IPTABLES=`which iptables`</p><p>$IPTABLES -F
$IPTABLES -t nat -F</p><p>$IPTABLES -P INPUT DROP
$IPTABLES -P OUTPUT ACCEPT
$IPTABLES -P FORWARD DROP</p><p>$IPTABLES -A INPUT -i lo -j ACCEPT
$IPTABLES -A INPUT -p tcp -m state &#8211;state ESTABLISHED,RELATED -j ACCEPT</p><p>$IPTABLES -A INPUT -p udp -j ACCEPT 
$IPTABLES -A INPUT -p icmp -j ACCEPT</p><p>А как настроен файрвол у вас на домашней машине?</p>]]></description>
</item>
</channel>
</rss>