|
From: Bruce S. <bw...@ar...> - 2003-05-29 14:10:09
|
> > INT_DEV=eth1 # internal/protected network.
> > OUT_DEV=eth0 # Internet
>
> I'm thinking of way so we could mark the interenal and external interface
> in the network scripts ifcfg-ethX. But haven't made up for a desicion yet.
> This way if would allow the firewall script to walk all installed
> interfaces and reference them and their status being eg. external, dmz,
> internal, ...
OK, let me know if/when that changes.
> > # Uncomment ALL lines starting with #LOG# to log rejected packets
> > #LOG# modprobe ipt_LOG
>
> Would that be much easier for the user:
> # Uncomment the following line to enable logging
> # LOGGING="yes"
>
> and you'd put such lines everywhere in the script:
> [ -n "$LOGGING" ] && ...command that does the logging
Good idea, it also allows it to be sent as a parameter. Will do.
> > ${IPTABLES} -P OUTPUT DROP # Drop all packets that are
>
> Hmmm...wouldn't do that with OUTPUT because then I guess you'd have to enable
> the some specific ICMP messages. Comments on that?
I have the basic setup in my home firewall, with that output policy of
drop, and pings work find through the firewall (forward), and from the
firewall itself. I don't know about other ICMP message types.
I'd leave it as drop to be safe, unless we can find something that
doesn't work.
> > # uncomment/modify next 3 lines to forward a service to an internal IP.
> > # SERVER=192.168.1.1 # Internal IP of server.
> > # PORT=22 # 22 = SSH. Change to 80 for web server, etc.
> > # ${IPTABLES} -A PREROUTING -i ${OUT_DEV} -t nat -p TCP --dport $PORT -j DNAT --to ${SERVER}:$PORT
>
> I had to add an additional
> $IPTABLES -A FORWARD -m state --state NEW -p tcp -i ${OUT_DEV} -o ${IN_DEV} -d ${SERVER} --dport ${PORT} -j ACCEPT
Yes, I dropped that line by mistake. Good catch.
> > # Prevent NetBIOS and Samba from leaking.
> > ${IPTABLES} -t nat -A PREROUTING -p TCP --dport 137:139 -j DROP
> > ${IPTABLES} -t nat -A PREROUTING -p UDP --dport 137:139 -j DROP
> > ${IPTABLES} -t nat -A PREROUTING -p TCP --dport 445 -j DROP
> > ${IPTABLES} -t nat -A PREROUTING -p UDP --dport 445 -j DROP
>
> Might want to consider Port 135 too.
The script I "borrowed" has 135:139 on the TCP chain and 137:139 on UDP.
How about using 135:139 on both lines?
> > # Log invalid packets:
> > #LOG# ${IPTABLES} -A INPUT -d 255.255.255.255 -j DROP # do not log broadcasts
> > #LOG# ${IPTABLES} -A INPUT -j LOG
> > #LOG# ${IPTABLES} -A FORWARD -j LOG
>
> For all the logging you might want to add limit options to not get into
> troubles when flouded with invalid or block packages (denial of service!)
Yes, I've seen those, ... somewhere.
Any idea where I "borrow" some samples?
> Also "--log-prefix" would be nice.
To identify where it was logged in the script?
> You might want to take a look at the example script of the IP-Tables
> tutorial http://iptables-tutorial.frozentux.net/
>
> You are missing the loading of modules, eg.
> $MODPROBE ip_conntrack > /dev/null 2>&1
> $MODPROBE ip_conntrack_ftp > /dev/null 2>&1
> $MODPROBE ip_nat_ftp > /dev/null 2>&1
They don't seem to be necessary in DL.
My running firewall.rules ONLY probes "ipt_LOG", and it works fine.
When I do a lsmod on my DL firewall (pre 0.6), I get all of these:
ipt_TOS 1048 3 (autoclean)
iptable_mangle 2168 1 (autoclean)
ipt_REJECT 3192 1 (autoclean)
ipt_state 568 7 (autoclean)
ipt_MASQUERADE 1368 1 (autoclean)
iptable_nat 17464 1 (autoclean) [ipt_MASQUERADE]
ip_conntrack 19360 2 (autoclean) [ipt_state ipt_MASQUERADE
iptable_nat]
iptable_filter 1740 1 (autoclean)
ipt_LOG 3384 4
ip_tables 12152 10 [ipt_TOS iptable_mangle ipt_REJECT
ipt_state ipt_MASQUERADE iptable_nat iptable_filter ipt_LOG]
So it appears they get loaded automatically, or some other script is
loading them. (I think it's automatic because of the "autoclean")
I'll make some changes, including the re-ordering you suggested, and
upload my changes.
- BS
|