Re: Iptable rules to protect my box from the internet

From: Andrew Schulman (andrex_at_deadspam.com)
Date: 12/28/04


Date: Tue, 28 Dec 2004 09:57:21 -0500


> I'm looking for a set of iptable rules, which will protect my linux box
> from incoming internet connections.
>
> My box's ip is 192.168.1.50 and my router is located at 192.168.1.100.
> Incoming and outgoing loopback connection and connections from the
> local lan are to be allowed.
>
> However, incoming tcp and udp connections not comming from either
> 127.0.0.1 or the local network 192.168.1.0 should be forbidden.
> Can somebody help me with this?

There's nothing you have to do. Your IP address, 192.168.1.50, isn't
routable over the internet; it's an internal IP reserved for LAN use.
What that means is that your router is performing network address
translation (NAT) between your internal and external IP addresses. It
has to be, or you wouldn't be receiving any internet traffic at all.

In order for NAT to work, it has to keep track of your outgoing
connections, so that it can properly route traffic back to you when
traffic comes in. But that means that any inbound traffic that doesn't
correspond to an existing connection can't reach you; if the router
doesn't recognize it as part of an existing connection, it doesn't know
where to send it, and simply drops it.

So, your router is already protecting you from all incoming connection
attempts. Only connections that you initiate will work.
Congratulations, you're done.

-- 
To reply by email, replace "deadspam.com" by "alumni.utexas.net"


Relevant Pages

  • RE: Remote access problem
    ... CEICW setting RWW is OK. ... I clicked "Connect to server desktops" and got the screen with all the ... Remote connections ... > Internet Connection wizard' to configure the server networking settings? ...
    (microsoft.public.windows.server.sbs)
  • Re: Evil monopolists and the future of the internet
    ... "The End of the Internet?" ... "The nation's largest telephone and cable companies are ... excess bandwidth after hours (I don't know if such is still ... multiple connections to a website based somewhere in Rio ...
    (sci.econ)
  • RE: IE Behavior
    ... I can start browsing the internet after about 20 minutes upon bootup... ... For the rest, I can open ssh connections in the meanwhile, I can even using ... I have XP sp2 and the latest patches. ... can then open CMD and ping web sites. ...
    (microsoft.public.windowsxp.general)
  • Re: were not number one
    ... The French Connections ... Europe and America, which spent more than six months on the Times ... new confidence reflected the rise of the Internet. ... particular, as dial-up has given way to broadband connections using DSL, ...
    (soc.retirement)
  • Re: Advanced Linksys routing question...
    ... Will RIP ... to the internet when one of my ISP's goes down? ... >> Linksys BEFSR41 routers handy. ... >> high-speed connections are working) and if one of the connections goes ...
    (comp.security.firewalls)