|
From: Friedrich L. <fl...@fl...> - 2003-05-28 23:55:52
|
Bruce Smith wrote: > I added a simple iptables script that supports 2 NIC's w/masquerading. > Please take a look, and comment: OK, I added the script code to be able to comment on it. > #!/bin/bash > # > # $Source: /cvsroot/devil-linux/build/config/etc/init.d/firewall.rules.2nic,v $ > # $Revision: 1.1 $ > # $Date: 2003/05/28 14:53:18 $ > # > # http://www.devil-linux.org > # > # > # Basic Firewall rules for 2 NIC's and NAT > # > > # Path to IPTABLES executable > IPTABLES=/usr/sbin/iptables > > INT_DEV=eth1 # internal/protected network. > OUT_DEV=eth0 # Internet I'm thinking of way so we could mark the interenal and external interface in the network scripts ifcfg-ethX. But haven't made up for a desicion yet. This way if would allow the firewall script to walk all installed interfaces and reference them and their status being eg. external, dmz, internal, ... > > echo "0" > /proc/sys/net/ipv4/ip_forward # stop forwarding while setting up. > > # Uncomment ALL lines starting with #LOG# to log rejected packets > #LOG# modprobe ipt_LOG Would that be much easier for the user: # Uncomment the following line to enable logging # LOGGING="yes" and you'd put such lines everywhere in the script: [ -n "$LOGGING" ] && ...command that does the logging > > # Flush & Policy > ${IPTABLES} -F # flush all chains > # flush all tables: > for t in `cat /proc/net/ip_tables_names`; do ${IPTABLES} -F -t $t ; done > ${IPTABLES} -X # delete all user chains > ${IPTABLES} -Z # zero all counters > ${IPTABLES} -P INPUT DROP # Policy = DROP > ${IPTABLES} -P OUTPUT DROP # Drop all packets that are Hmmm...wouldn't do that with OUTPUT because then I guess you'd have to enable the some specific ICMP messages. Comments on that? > ${IPTABLES} -P FORWARD DROP # not specifically accepted. > > # Masquerading (aka NAT, PAT, ...) > ${IPTABLES} -t nat -A POSTROUTING -o ${OUT_DEV} -j MASQUERADE > > # uncomment/modify next 3 lines to forward a service to an internal IP. > # SERVER=192.168.1.1 # Internal IP of server. > # PORT=22 # 22 = SSH. Change to 80 for web server, etc. > # ${IPTABLES} -A PREROUTING -i ${OUT_DEV} -t nat -p TCP --dport $PORT -j DNAT --to ${SERVER}:$PORT I had to add an additional $IPTABLES -A FORWARD -m state --state NEW -p tcp -i ${OUT_DEV} -o ${IN_DEV} -d ${SERVER} --dport ${PORT} -j ACCEPT But I would first add the state rules below and than add any new rules. > > # Allow connections to the internet. > #LOG# ${IPTABLES} -A FORWARD -m state --state NEW,INVALID -i ${OUT_DEV} -j LOG > ${IPTABLES} -A FORWARD -m state --state NEW,INVALID -i ${OUT_DEV} -j DROP > ${IPTABLES} -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT > ${IPTABLES} -A FORWARD -m state --state NEW -i ${INT_DEV} -j ACCEPT > > # Prevent NetBIOS and Samba from leaking. > ${IPTABLES} -t nat -A PREROUTING -p TCP --dport 137:139 -j DROP > ${IPTABLES} -t nat -A PREROUTING -p UDP --dport 137:139 -j DROP > ${IPTABLES} -t nat -A PREROUTING -p TCP --dport 445 -j DROP > ${IPTABLES} -t nat -A PREROUTING -p UDP --dport 445 -j DROP Might want to consider Port 135 too. > > # Allow our firewall to connect. > ${IPTABLES} -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT > ${IPTABLES} -A OUTPUT -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT As above. I'd group those state related rules right after clearing the chains. > > # Allow Ping and friends. > ${IPTABLES} -A OUTPUT -p icmp -j ACCEPT > ${IPTABLES} -A INPUT -p icmp -j ACCEPT > > # We accept anything from the inside. > ${IPTABLES} -A INPUT -i ${INT_DEV} -j ACCEPT > ${IPTABLES} -A INPUT -i lo -j ACCEPT > ${IPTABLES} -A OUTPUT -o ${INT_DEV} -j ACCEPT > ${IPTABLES} -A OUTPUT -o lo -j ACCEPT As the lo is essential I'd move it right after the state related (EST/RELATED) rules. And tell the user to never ever remove them. > > # Fast reject for Ident to eliminate email delays. > ${IPTABLES} -A INPUT -p TCP --dport 113 -i ${OUT_DEV} -j REJECT --reject-with tcp-reset > > # make interactive sesions a bit more interactive under load > ${IPTABLES} -A PREROUTING -t mangle -p TCP --sport ssh -j TOS --set-tos Minimize-Delay > ${IPTABLES} -A PREROUTING -t mangle -p TCP --sport ftp -j TOS --set-tos Minimize-Delay > ${IPTABLES} -A PREROUTING -t mangle -p TCP --sport ftp-data -j TOS --set-tos Maximize-Throughput > > # Log invalid packets: > #LOG# ${IPTABLES} -A INPUT -d 255.255.255.255 -j DROP # do not log broadcasts > #LOG# ${IPTABLES} -A INPUT -j LOG > #LOG# ${IPTABLES} -A FORWARD -j LOG For all the logging you might want to add limit options to not get into troubles when flouded with invalid or block packages (denial of service!) Also "--log-prefix" would be nice. > > # enable dynamic IP address following > echo 7 > /proc/sys/net/ipv4/ip_dynaddr > > # stop some smurf attacks. > echo 1 > /proc/sys/net/ipv4/icmp_echo_ignore_broadcasts > > # Don't accept source routed packets. > echo "0" > /proc/sys/net/ipv4/conf/all/accept_source_route > > # Syncookies > echo "1" > /proc/sys/net/ipv4/tcp_syncookies > > # Stop IP spoofing, > for interface in /proc/sys/net/ipv4/conf/*/rp_filter; do > echo "1" > $interface > done > > # Stop ICMP redirect > for interface in /proc/sys/net/ipv4/conf/*/accept_redirects; do > echo "0" > ${interface} > done > > # Enable bad error message protection. > /bin/echo "1" > /proc/sys/net/ipv4/icmp_ignore_bogus_error_responses > > # Enabling IP forwarding. > echo "1" > /proc/sys/net/ipv4/ip_forward You might want to take a look at the example script of the IP-Tables tutorial http://iptables-tutorial.frozentux.net/ You are missing the loading of modules, eg. $MODPROBE ip_conntrack > /dev/null 2>&1 $MODPROBE ip_conntrack_ftp > /dev/null 2>&1 $MODPROBE ip_nat_ftp > /dev/null 2>&1 -- MfG / Regards Friedrich Lobenstock ____________________________________________________________________ Friedrich Lobenstock Linux Services Lobenstock URL: http://www.lsl.at/ Email: fl...@fl... ____________________________________________________________________ |