iptables input DROP rule

From: Tony (tony.wong@stanford.edu)
Date: 05/29/02


From: "Tony" <tony.wong@stanford.edu>
Date: Wed, 29 May 2002 14:17:52 -0700

Trying to setup iptables firewall on a web server.

I have the policy as follows:

*filter
:INPUT DROP
:FORWARD DROP
:OUTPUT ACCEPT

-A INPUT -i eth1 -f -j DROP
-A INPUT -i eth1 -p tcp -m state --state INVALID -j DROP
-A INPUT -i eth1 -p tcp -m state --state NEW -m tcp ! --tcp-flags
SYN,RST,ACK SYN -j DROP
-A INPUT -i eth1 -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -m limit --limit
1/sec -j ACCEPT
-A INPUT -i eth1 -p tcp -m tcp --tcp-flags FIN,SYN,RST,ACK RST -m
limit --limit 1/sec -j ACCEPT

 -A INPUT -i eth1 -p tcp -m state --state ESTABLISHED -m tcp --dport 80 -j
ACCEPT

Then when I try to access a web page on this server. The page comes up but
very very slow. Like some graphics are not being loaded.

Then I changed the rule to:

:INPUT ACCEPT

and then the page and graphics loaded very quickly. Why is that. What ports
do I need to open?

Thanks



Relevant Pages

  • iptables input DROP rule
    ... Trying to setup iptables firewall on a web server. ... I have the policy as follows: ... SYN,RST,ACK SYN -j DROP ...
    (comp.os.linux.security)
  • How to secure a WEB Server on a workstation on an Intranet with IPSec ?
    ... My workstation is Windows XP Pro SP2 on a company intranet (static IP ... I want to install and use a localised WEB Server ... Action> Manage IP filter lists and filter actions. ... Manage Filter Action Tab ...
    (comp.os.ms-windows.nt.admin.security)
  • Packet filter statistics
    ... I've got a Windows 2000 web server that is spewing out over 2Mbps of ... data which is going out round robin over my 3 T-1 connections. ... as well as each packets frequency and size. ... Anyone familiar with available software that I could dump on my filter ...
    (freebsd-questions)
  • [TOOL] HTTP Filter - HTTP Tunneling and Filtering Tool
    ... HTTP Filter - HTTP Tunneling and Filtering Tool ... filtering and multiplexing that is positioned in front of the web server - ...
    (Securiteam)
  • Re: Linux traffic shaping problem
    ... Actually I have a box running linux with two cards, ... I want to filter all traffic: what's going through the router, ... Currently the router and web server work Ok. ...
    (RedHat)