Re: Blocking incoming IP address immediately

From: Nico Declerck (Nico.Declerck_at_UGent.be)
Date: 11/30/04


Date: Tue, 30 Nov 2004 15:23:38 +0100

Jeff Franks wrote:

>> Just one question to be on the safe side... The iptables-firewall and the
>> "Roger Wilco" game are one and the same machine??? right?
>
> No the iptables firewall is on a stand-alone RedHat 9 server. It's only
> function right now is to provide NAT and a firewall for my internal LAN.
> The game and the Roger Wilco are on a seperate server and the ports are
> forwarded in to it. That, by the way, is working like a champ. The game
> is
> up and the RW is working fine. My only issue is how to block specific IP
> addresses on the fly without effecting the other connections.

What I don't understand then is why you try to block them in the
INPUT-chain.... You should try the FORWARD chain...

The INPUT chain is used strictly for processes that run on your firewall, if
the game server is another machine, the packets will go through the FORWARD
chain, even if the firewall has to perform NAT.

prompt



Relevant Pages

  • Re: IP Addressing
    ... Address of the ISA server? ... firewall and router). ... On the firewall create a static NAT entry as I wrote ...
    (comp.dcom.sys.cisco)
  • Re: CEICW fails at firewall config
    ... Do you or do you not have ISA 2000 or ISA 2004 installed on the SBS server? ... Do you have 2 NICs in the SBS? ... CEICW fails on firewall configuration every time. ... >>> Call to Creating the protected networks access rule returned ok. ...
    (microsoft.public.windows.server.sbs)
  • Re: IP Relay/NAT set up on W2K3
    ... NAT on the perimeter, then "proxy" the connection to the internal server. ... is a requirement,...the firewall is "in the way", and the only way into the ...
    (microsoft.public.windows.server.networking)
  • Re: Recycler security issues on IIS server
    ... > latest upates to the server. ... > like to see the server put behind our firewall, ... other software, install all patches, IISlockdown, URLscan, use the correct ... the procedures you follow may vary depending on your security needs. ...
    (microsoft.public.inetserver.iis.security)
  • Re: WSS v.3 BETA 2 - FQDN REQUIRED for external access?
    ... I'm not sure I follow the question, but I can tell you that I'm doing NAT ... firewall to an internal IP address won't SharePoint think it's talking to ... Mine went into the default zone, so if that's your only option you're ... I installed this server over a week ago and still cannot access ...
    (microsoft.public.sharepoint.windowsservices)