Re: Syncing iptables rules between two servers



I could think of a

cron job running every hour on server A where you would like to copy
the rules. Transfer the file where the rules are to Server B.

Things to remmeber here are transfer the large file using scp .. You
could limit the login for passwordless ssh only from this machine or
ip.

At server B check for this file and if present append the file and
restart iptables. Can be done using a cron job ..

./thanks
ilaiy

On 4/8/06, Lars Solberg <sunberg@xxxxxxxxx> wrote:
Hi

Is there anyone that know about how I can "sync" iptables rules on two
different servers? The plan is to have (on one of the servers) a
script that automaticly block ip adresses with iptables depending on
different conditions. When that ip adress is blocked I want it to
automaticly be blocked on another server to.

One idea is to change the script that is adding the block rule to
iptables to make it soo it can send the rule to the other server, but
this is not an option, the iptables rules must be synced after the
iptables rule have been added.
Another idea is to get the iptables to use an sql database of some
sort to load the rules, but I dont know how, and this whould be
somehow ruining the whole thing of having a firewall if you make it
dependent an sql server (i think).. But afterall, if this is possible
this is option.

Any ideas?
Hope someone can help out..

Thanks
Lars




Relevant Pages

  • Re: NIS client couldnt log in
    ... >> off iptables, the client bound to the server and all the yptools ... and ypbind in broadcast mode (ypcat and ypwhich would ... >> work at all if i specified the server). ... Further, ypbind uses the ...
    (RedHat)
  • Need help configuring IPtables w/ DMZ, 2 LAN, and INET
    ... I am desperately in need of assistance in configuring an IPtables ... firewall on a Red Hat Linux 9.0 server. ... Chain FORWARD ... tcp dpt:25 flags:0x16/0x02 ...
    (comp.os.linux.networking)
  • Static IP w/ PPPoe xDSL Firewall
    ... iptables -F -t nat ... # Kill malformed XMAS packets ... # Refuse incoming packets pretending to be from the external address. ... # server/client to server query or response ...
    (comp.os.linux.networking)
  • Re: Modprobe question
    ... >> Made some minor changes to iptables and did a restart. ... >> modprobe seems to be doing something but I can't tell what. ... >> course the server seems to be running fine. ...
    (alt.linux)
  • losing connection to server when scanned by nmap - Iptables
    ... The iptables script applied to the NIC is shown below. ... the web server or ssh into the server when I do this scan. ... echo 2> $f ... # Refuse packets claiming to be from a Class A private network. ...
    (comp.security.firewalls)