Difference between revisions of "Iptables"
Jump to navigation
Jump to search
↑ https://serverfault.com/a/608976
Line 18: | Line 18: | ||
Block all but a range | Block all but a range | ||
+ | iptables -I OUTPUT --dst-range <remote_ip> -j ACCEPT | ||
+ | iptables -I INPUT --src-range <remote_ip> -j ACCEPT | ||
+ | iptables -I OUTPUT --dst-range <remote_ip> -j ACCEPT | ||
+ | iptables -I INPUT --src-range <remote_ip> -j ACCEPT | ||
+ | iptables -P INPUT DROP | ||
+ | iptables -P OUTPUT DROP | ||
+ | |||
+ | |||
+ | Block all but one IP | ||
iptables -I OUTPUT -d <remote_ip> -j ACCEPT | iptables -I OUTPUT -d <remote_ip> -j ACCEPT | ||
iptables -I INPUT -s <remote_ip> -j ACCEPT | iptables -I INPUT -s <remote_ip> -j ACCEPT |
Revision as of 07:36, 22 March 2020
iptables
command line utility allows to modify Linux kernel firewall rules.
Contents
Basic commands
sudo iptables -L
iptables-save
andiptables-restore
Examples
KVM VNC remote viewer iptables -t nat -A PREROUTING -i eno1 -p tcp --dport 5900 -j DNAT --to 127.0.0.1:5900 sysctl -w net.ipv4.ip_forward=1 sysctl -p /etc/sysctl.conf
- Block all output traffic:
iptables -A OUTPUT -o ethXXX -j DROP
Block all but a range
iptables -I OUTPUT --dst-range <remote_ip> -j ACCEPT iptables -I INPUT --src-range <remote_ip> -j ACCEPT iptables -I OUTPUT --dst-range <remote_ip> -j ACCEPT iptables -I INPUT --src-range <remote_ip> -j ACCEPT iptables -P INPUT DROP iptables -P OUTPUT DROP
Block all but one IP
iptables -I OUTPUT -d <remote_ip> -j ACCEPT iptables -I INPUT -s <remote_ip> -j ACCEPT iptables -I OUTPUT -d <remote_ip> -j ACCEPT iptables -I INPUT -s <remote_ip> -j ACCEPT iptables -P INPUT DROP iptables -P OUTPUT DROP
Activities
- Read iptables Ubuntu howto: https://help.ubuntu.com/community/IptablesHowTo
- Read archlinux documentation: https://wiki.archlinux.org/index.php/iptables
- Read Stackoverflow iptables questions: https://stackoverflow.com/questions/tagged/iptables?tab=Votes
- Review your current iptables configuration
See also
iptables
ufw
firewalld
nftables
firewall-cmd
ipfw (FreeBSD)
PF (OpenBSD)
, netsh advfirewallnftables
firewall-cmd
- Palo Alto firewalls: PAN-OS
- Port knocking,
fail2ban
[1]fwknop
, DenyHosts
Advertising: