Re: Syncing iptables rules between two servers



Hi,

You can use iptables-save and iptables-restore utilities to do this, but in
this case you need to find a way to share the file which contains the iptables-
save result and to read this file to perform iptables-restore operation.

Regards,
Stoimen Gerenski


Lars Solberg <sunberg@xxxxxxxxx>:

Hi

Is there anyone that know about how I can "sync" iptables rules on two
different servers? The plan is to have (on one of the servers) a
script that automaticly block ip adresses with iptables depending on
different conditions. When that ip adress is blocked I want it to
automaticly be blocked on another server to.

One idea is to change the script that is adding the block rule to
iptables to make it soo it can send the rule to the other server, but
this is not an option, the iptables rules must be synced after the
iptables rule have been added.
Another idea is to get the iptables to use an sql database of some
sort to load the rules, but I dont know how, and this whould be
somehow ruining the whole thing of having a firewall if you make it
dependent an sql server (i think).. But afterall, if this is possible
this is option.

Any ideas?
Hope someone can help out..

Thanks
Lars



---------------------------------------------------
Webmail of Bulsat Ltd. at http://mail.bulsattv.com/


-------------------------------------------------------------------------
This List Sponsored by: Webroot

Don't leave your confidential company and customer records un-protected.
Try Webroot's Spy Sweeper Enterprise(TM) for 30 days for FREE with no
obligation. See why so many companies trust Spy Sweeper Enterprise to
eradicate spyware from their networks.
FREE 30-Day Trial of Spy Sweeper Enterprise

http://www.webroot.com/forms/enterprise_lead.php
--------------------------------------------------------------------------



Relevant Pages

  • Re: Syncing iptables rules between two servers
    ... Transfer the file where the rules are to Server B. ... Can be done using a cron job .. ... Is there anyone that know about how I can "sync" iptables rules on two ... Try Webroot's Spy Sweeper Enterprisefor 30 days for FREE with no ...
    (Security-Basics)
  • Re: Forwarding to mail server : problem accessing from local network
    ... I will study again kerrocher's iptables rules, but I don't think I have ... I would rather think that "amd64" doesn't accept response from ... partir d'un poste sur Internet. ... I thougth my forwarding iptables rules were wrong on local network. ...
    (comp.os.linux.networking)
  • Re: some reality about iptables, please
    ... constructing your own iptables rules, I suggest you seriously look at ... great scripts for platform hardening but I prefer shorewall's firewall ... counterparts) to save and restore the configuration. ... > iptables rules, says that's not enough, and speaks not at all (that I've ...
    (Debian-User)
  • Re: my iptables setting not loaded after reboot in fc5
    ... First you should set the iptables rules to what you desire. ... survive after a reboot. ... it gets even worse -- erased all of my settings and put something ...
    (Fedora)
  • A bit OT: iptables rules for simple network traffic accounting
    ... using 2 additional iptables rules ... packets travel through the system like this ... Is the iptables' MARK target ...
    (Debian-User)