Re: Problem with Samba and iptables

From: Jeremy Gray (gray@euthanasia.ath.cx)
Date: 03/20/03


From: Jeremy Gray <gray@euthanasia.ath.cx>
Date: Thu, 20 Mar 2003 05:42:39 GMT

Nada Lada <nadalada@linux.lan> wrote:
> On Wed, 19 Mar 2003 21:17:16 -0700, Jeremy Gray wrote:
>>
>> So, you could allow all packets destined for 192.168.0.0/24 in your
>> samba rules or just 192.168.0.255 for a 255.255.255.0 netmask.
>> Either way your firewall will allow incoming packets destined for the
>> broadcast address.
>
> If I'm following your reasoning, where I originally have the source as
> $INTRANET (192.168.0.0/24) and the destination as $IPADDR
> (192.168.0.1), I should change the destination to $INTRANET as well.
> My goal is to only accept packets that originate on my internal
> network. Am I on correct here?

Yeah. That looks good.

-- 
Jeremy A. Gray
gray@metacomet.net
"Remember the Pueblo." -- the Fourth Law of Marvin


Relevant Pages

  • SunScreen and Broadcasts
    ... firewall and have had a lot of frustration trying to get help ... through Sun's support. ... interface on the backup network isn't even connected. ... traffic to the broadcast address of the internal ...
    (Focus-SUN)
  • TCP Connections to a Broadcast Address on BSD-Based Systems
    ... BSD-based TCP/IP code has a bug with respect to creating TCP ... TCP implementation works correctly and do not block broadcast ... firewall host or gateway, the potential for exploitation is probably ...
    (Bugtraq)
  • Re: TCP - UDP Ports used in file sharing & associated anomolies
    ... I would think a router would be a much ... > The firewall isn't for security reasons... ... > It segregates a hardware lab from the production network. ... this is b/c the hardware being developed emits a broadcast UDP packet every ...
    (microsoft.public.windows.server.networking)
  • Re: iptables DNAT --to-destination problem
    ... > No sane router will forward a general broadcast. ... >> The generated package can not be logged by the Firewall, ... After that includes the firewall doesnt logg FORWARD packages too :-( ... The computer B can't sniff the Broadcast message on eth1, ...
    (comp.os.linux.security)
  • Re: cisco 1600
    ... Ask your "guru" to justify his reasoning. ... installed firewal is worse than no firewall> With out a firewall, ... Network person had some trouble ...
    (comp.security.firewalls)