Re: Syncing iptables rules between two servers



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Lars Solberg typed:

Is there anyone that know about how I can "sync" iptables rules on
two different servers? The plan is to have (on one of the servers) a
script that automaticly block ip adresses with iptables depending on
different conditions. When that ip adress is blocked I want it to
automaticly be blocked on another server to.

One idea is to change the script that is adding the block rule to
iptables to make it soo it can send the rule to the other server,
but this is not an option, the iptables rules must be synced after
the iptables rule have been added. Another idea is to get the
iptables to use an sql database of some sort to load the rules, but
I dont know how, and this whould be somehow ruining the whole thing
of having a firewall if you make it dependent an sql server (i
think).. But afterall, if this is possible this is option.

Have a look at the man pages for iptables-save(8) and
iptables-restore(8). One can create a script to dump iptables rules
via iptables-save(8) at some intervals, contrast the dump output with
a previously saved copy of the dumped rules, extract the differences
into a file, move the file over to the other system, and use the '-n'
or "--noflush" option to iptables-restore(8) to include the extra
rules into the ruleset. That might well work.

- --
Ayaz Ahmed Khan

Indifference will be the downfall of mankind, but who cares?

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)
Comment: For info see http://quantumlab.net/pine_privacy_guard/

iQEVAwUBRDpdNQFi6bOwa2ADAQKfZAf/ViJZAZ9PqYTtnprgCAU12YIjvQBsfIaj
FGF9yeOlkLU9Y9Sw/S6QV4k6bGBELY+gJzmV+tsRvV4jBPS4f95pCdBIBO0MVMgE
YMrAI5B6Xroj9N8c9UDPrkag5kEggLrDr301q7/bZA+EmnSefpkAzSPmmdNQxQz2
yHHQIsNqv9XN94x7D4O6VokKPTsSPDiCrhCMTf5+vJqvy2aVtOWeWpfT1paxXjPg
vr+q5bkFhuUDs4xB9Mjh2jrwqiFBe1xOwRpWpsOryIzoKEKB693xImkopPjF+Nf+
QHs1pSb3Uk2DcKszbYKvBS4k8fRmbfUONMPiVED0c+ey0aFoFg/lRg==
=rfc6
-----END PGP SIGNATURE-----



Relevant Pages

  • Re: losing connection to server when scanned by nmap - Iptables
    ... >> server, ... >> The iptables script applied to the NIC is shown below. ... >> # Refuse packets claiming to be from a Class A private network. ...
    (comp.security.firewalls)
  • Re: Syncing iptables rules between two servers
    ... script that automaticly block ip adresses with iptables depending on ... automaticly be blocked on another server to. ... One idea is to change the script that is adding the block rule to ...
    (Security-Basics)
  • Re: NIS client couldnt log in
    ... >> off iptables, the client bound to the server and all the yptools ... and ypbind in broadcast mode (ypcat and ypwhich would ... >> work at all if i specified the server). ... Further, ypbind uses the ...
    (RedHat)
  • Re: firewall howto - iptables
    ... which is quite a bit easier than writing rules for iptables ... My ubuntu server is acting as my NAT box between my upstream provider ... Might somebody have a good example script they can send me or a HOWTO ...
    (Ubuntu)
  • Need help configuring IPtables w/ DMZ, 2 LAN, and INET
    ... I am desperately in need of assistance in configuring an IPtables ... firewall on a Red Hat Linux 9.0 server. ... Chain FORWARD ... tcp dpt:25 flags:0x16/0x02 ...
    (comp.os.linux.networking)