Re: A Question On Ipchains Input Rules

From: Newsbox (newsbox_at_MAPS_ON_customers-of-adelphia.org)
Date: 12/25/03

  • Next message: Ronaldo Vasconcellos: "Re: Security through wide system use?"
    Date: Thu, 25 Dec 2003 03:40:36 -0500
    
    

    On Wed, 24 Dec 2003 19:08:25 -0500, Thomas Dineen wrote:

    > Gentlepeople:
    >
    > I am having a strange difficulty with ipchains on
    > RedHat 7.2. The forwarding rules shown below work great when used stand
    > alone without the input rules. The performance of the forwarding rules
    > seems to match that described in the documentation and also seems
    > intuitive.
    > [...]

    One thing you are doing wrong is to be using ipchains instead of iptables.
     No one uses ipchains, because iptables is better. iptables came online
    with the 2.4 kernel, quite some time ago. If you are not using at least a
    2.4 kernel, then (sorry to say) you are hopelessly out of date. Your
    Internet-connected security will suffer, whatever ipchains rules that you
    set. ... Looks like you have some reading to do. Try:

    man chkconfig

    ipchains must be set to _not_ start if you expect iptables to work.

    man iptables

    People get paid good money to write books on iptables, and I am not one
    of them. But this is where you start.

    Sorry that I didn't critique the rest of your post; I thought this was
    the best suggestion I could make.

    Best wishes.

    -- 
    Remove the backwards _NO_SPAM for e-mail
    	... Trying to cut down on the backwards NEWS virus mail
    Thanks !!
    

  • Next message: Ronaldo Vasconcellos: "Re: Security through wide system use?"

    Relevant Pages

    • Re: Prevent access to linux server when mac adress does not match ip adress
      ... Iptables has much more features than ipchain. ... Prior to the 2.2.x kernel, the firewall was controlled by "ipfwadm". ... introduced the IPCHAINS tool to control that. ... Often the upgrade is too big and bulky for the older ...
      (comp.os.linux.networking)
    • Re: IPChains with RH 9? "Protocol not available"
      ... Yes, iptables is way more versatile than ipchains, and ipchains ... is no longer supported in the redhat kernel by default. ... is RH 9 stock kernel still support ipchains? ...
      (RedHat)
    • Re: A Question On Ipchains Input Rules
      ... If RH72 allows using iptables instead of ipchains, ... return packets for any established connections, ... outbound SMTP sessions, you just allow outbound SMTP, and the ...
      (comp.os.linux.security)
    • Re: IPChains not working
      ... >>and changing a script from ipchains to iptables can take a while ... The only people for me are the mad ones -- the ones who are mad to live, ... the ones who never yawn or say a commonplace thing, but burn, burn, burn ...
      (comp.os.linux.security)
    • Re: IPChains with RH 9? "Protocol not available"
      ... Iptables is now the default, but it looks like ipchains is still included. ... Red Hat firewall config tools to help out any more. ... Clemson University Math Sciences ...
      (RedHat)