All about iptables

Discuss Networking
User avatar
Void Main
Site Admin
Site Admin
Posts: 5716
Joined: Wed Jan 08, 2003 5:24 am
Location: Tuxville, USA
Contact:

Post by Void Main »

Well I do Xterminal server into my desktop in the kitchen but that is not why I don't have to go downstairs and get on the console of the servers. The reason I don't have to go to the console is because I just ssh into the servers and do everything from the command line. I don't even have X installed on them so I wouldn't get any more benefit from being at the console than I have with ssh.

bazoukas
programmer
programmer
Posts: 192
Joined: Tue Jan 14, 2003 1:38 pm
Location: NYC
Contact:

Post by bazoukas »

Void before I do anything and mess up my system I just need to make sure about the syntax with iptables.

Say just for example I want to deny connection to port 6000,

I would need to type this (no?)

Code: Select all

iptables -A INPUT -p tcp --sport 6000 -j REJECT

There is no need to put the actual name of the service right?
At least thats what am reading in the Official Document from RH.[/code]

User avatar
Void Main
Site Admin
Site Admin
Posts: 5716
Joined: Wed Jan 08, 2003 5:24 am
Location: Tuxville, USA
Contact:

Post by Void Main »

Actually you would want "--dport" rather than "--sport". But I don't understand, 6000 should already be blocked to everything except your local internal network if you added the rules from last night. You can use REJECT or DROP as the action (REJECT sends and error message back, DROP doesn't, both will deny access). Also you did not specify an interface which means you would block incoming port 6000 on all interfaces.

bazoukas
programmer
programmer
Posts: 192
Joined: Tue Jan 14, 2003 1:38 pm
Location: NYC
Contact:

Post by bazoukas »

I brought 6000 just for an example. Right now I am reinstalling RedHat8 in my laptop (was trying debian on it during the weekend) and I will do everything in my laptop from scratch so i wont mess up anything in this computer.


Oh I see now. I need to specify if its going to be in eth0 or eth1 and so on, otherwise its like apllying it to all interfaces.

Install just finished in laptop. I will give it a try now.

bazoukas
programmer
programmer
Posts: 192
Joined: Tue Jan 14, 2003 1:38 pm
Location: NYC
Contact:

Post by bazoukas »

Whoooozaaa!!!!!!

I did it using the shell saved it and then did -L and it was right there and then I restarted it.
All was [OK] .

Man this is fun as hell. You can write ANY rules you want!!

User avatar
Void Main
Site Admin
Site Admin
Posts: 5716
Joined: Wed Jan 08, 2003 5:24 am
Location: Tuxville, USA
Contact:

Post by Void Main »

Yeah, when things start "clicking" that is when the real fun begins...

bazoukas
programmer
programmer
Posts: 192
Joined: Tue Jan 14, 2003 1:38 pm
Location: NYC
Contact:

Post by bazoukas »

Allright mano,,,,am going to ze bed. In two days I slept for 4 hours. Last night i stoped for a min with Linux turned my chair towards the TV set and I just slept like a dog on the chair till almost 6 in the morning.


Void thanks ALOT man. This is like attending another course during nights.
Thanks a million. If you werent married I would send you some naked greek girls your way :twisted:

Post Reply