Which port to block for ping, and how?

From: Anthony Campbell (me_at_privacy.net)
Date: 12/18/03


Date: 18 Dec 2003 09:44:50 GMT


I've recently set up an ADSL line so am worried about security. This is
a standalone computer, not a LAN.

A test shows that it is possibe to ping my machine, which I gather is a
Bad Thing. I am still at a very early stage of struggling to understand
iptables (had no luck with the setup scripts I've tried so will do it
manually).

Can anyone suggest how I could go about blocking this access (particular
port or ports?) without cutting myself off from the internet, which is
what happens with most of the things I try with iptables.

Or could I do this with portsentry?

A.

-- 
Using Linux GNU/Debian - Windows-free zone
http://www.acampbell.org.uk (book reviews and articles)
Email: replace "www." with "ac@"


Relevant Pages

  • RE: redhat-list Digest, Vol 4, Issue 38
    ... Re: Iptables: port 22 open only for my IP ... Windows Services for Unix 3.5 ... It does absolutely nothing if you have a rampant application on your Windows box that opens a port to the outside world. ...
    (RedHat)
  • Firewall Rules Summary
    ... Subject: Firewall Rules Summary ... This script is provided "as is" with no implied warranty. ... this came from various howtos and articles on iptables that existed around ... #specific port denies>1024 tcp ...
    (Focus-Linux)
  • Re: pf and ftp from gateway
    ... # ephemeral port, so that the remote SIP proxy knows what session we belong ... pass in quick on $ext_if inet proto udp from any port bootps to ... pass out quick on $ext_if inet proto udp from $ext_if to any port bootps ... # allow lan requests from lan clients to exit EXT ...
    (comp.unix.bsd.openbsd.misc)
  • Re: Linux IPTables tutorial pdfs and plain text available.
    ... What you are referring to here are CHAINS. ... create as a user-defined chain in my iptables scripts to reject traffic ... need to allow port 20/tcp only if you're using active FTP. ... This is actually not a bash script, ...
    (comp.security.firewalls)
  • active ftp
    ... Does anyone have a pf config for active ftp? ... # Redirect lan client FTP requests ... # to the ftp-proxy running on the firewall host (via inetd on port 8021) ... rdr on $int_if inet proto tcp from $int_if:network to any port www -> ...
    (comp.unix.bsd.openbsd.misc)

Quantcast