RE: iptables & tcp wrappers

From: Whelan, Paul (Paul.Whelan_at_fmr.com)
Date: 10/11/04

  • Next message: TJ Easter: "Re: iptables & tcp wrappers"
    Date: Mon, 11 Oct 2004 12:23:02 -0400
    To: <focus-linux@securityfocus.com>
    
    

    On 2004-09-29 harry wrote:
    > Whelan, Paul wrote:
    > > "iptables -L --line-numbers" will show you the line numbers of the
    > > rules.
    > > "iptables -A INPUT -p tcp -s ! ONLY_IP_YOU_WANT --dport 22 -j DROP"
    will
    > > block every connection to port 22 except ONLY_IP_YOU_WANT.
    >
    > not really... a good firewall (IMHO) drops everything, rejects auth
    > (nasty timeouts on ftp, irc, ... if you just drop auth), and accepts
    > these 4(or 5) icmp requests:
    > "source-quench"
    > "parameter-problem"
    > "time-exceeded"
    > "destination-unreachable"
    > and your clients probably want the "echo-request" too :)

    Just so it's clear...
    The question wasn't in regards to what was a "good" firewall. The
    question was about asking how to only allow a certain ip to connect to
    port 22 and reject the rest. That rule will do that and do it well.
    Trust me. Try it on your server and see.
    If the scope of the question was "What makes a good firewall?". Then
    that would have been more than a single rule. <obviously>.
    Thanks,
    Paul


  • Next message: TJ Easter: "Re: iptables & tcp wrappers"

    Relevant Pages

    • Re: Slow response in Outlook on SBS2003
      ... I would not turn off the firewall on the XP's. ... Regards, ... >> Marina Roos ... >> Microsoft SBS-MVP ...
      (microsoft.public.windows.server.sbs)
    • Re: Not able to connect to the machine using RDP
      ... Already i have disabled the firewall, still i am not able to connect. ... Regards ... > Have you tried disabling the firewall on the target machine? ... source terminal service with the description terminal service ...
      (microsoft.public.windowsxp.general)
    • Re: micro$oft firewall *is* good for something
      ... >> regards, ... >For one thing...doesn't XP have a built-in Remote access? ... how would anyone be able to get remote support if he can't get ... >From the comments I have seen here about Microsoft's firewall, ...
      (comp.security.firewalls)
    • Re: micro$oft firewall *is* good for something
      ... >> regards, ... >For one thing...doesn't XP have a built-in Remote access? ... how would anyone be able to get remote support if he can't get ... >From the comments I have seen here about Microsoft's firewall, ...
      (comp.security.firewalls)
    • Re: Manual startup sever with TCP/IP
      ... have any relevance with regards to the TCP/IP connection. ... > Also check your firewall settings -- they often interfere. ...
      (microsoft.public.windowsce.platbuilder)