|
From: Friedrich L. <fl...@fl...> - 2003-05-29 14:29:50
|
Bruce Smith wrote:
>>I'm thinking of way so we could mark the interenal and external interface
>>in the network scripts ifcfg-ethX. But haven't made up for a desicion yet.
>>This way if would allow the firewall script to walk all installed
>>interfaces and reference them and their status being eg. external, dmz,
>>internal, ...
>
> OK, let me know if/when that changes.
Ok, but currently I don't know if what is practicable at all and how
to do it then. Currently just an idea. But I will let you know.
>>># Prevent NetBIOS and Samba from leaking.
>>>${IPTABLES} -t nat -A PREROUTING -p TCP --dport 137:139 -j DROP
>>>${IPTABLES} -t nat -A PREROUTING -p UDP --dport 137:139 -j DROP
>>>${IPTABLES} -t nat -A PREROUTING -p TCP --dport 445 -j DROP
>>>${IPTABLES} -t nat -A PREROUTING -p UDP --dport 445 -j DROP
>>
>>Might want to consider Port 135 too.
>
> The script I "borrowed" has 135:139 on the TCP chain and 137:139 on UDP.
>
> How about using 135:139 on both lines?
Would not do this as Port 136 is not related to Windows and there
might be a valid service using it.
>>># Log invalid packets:
>>>#LOG# ${IPTABLES} -A INPUT -d 255.255.255.255 -j DROP # do not log broadcasts
>>>#LOG# ${IPTABLES} -A INPUT -j LOG
>>>#LOG# ${IPTABLES} -A FORWARD -j LOG
>>
>>For all the logging you might want to add limit options to not get into
>>troubles when flouded with invalid or block packages (denial of service!)
>
>
> Yes, I've seen those, ... somewhere.
> Any idea where I "borrow" some samples?
See the iptables tutorial I referenced at the end of my last mail.
>>Also "--log-prefix" would be nice.
>
>
> To identify where it was logged in the script?
Exactelly. See iptables tutorial.
>>You might want to take a look at the example script of the IP-Tables
>>tutorial http://iptables-tutorial.frozentux.net/
As the site seems to have connectivety problems see
http://www.bec.at/support/iptables-tutorial/
http://www.bec.at/support/iptables-tutorial/examplecode.html
>>You are missing the loading of modules, eg.
>>$MODPROBE ip_conntrack > /dev/null 2>&1
>>$MODPROBE ip_conntrack_ftp > /dev/null 2>&1
>>$MODPROBE ip_nat_ftp > /dev/null 2>&1
>
> They don't seem to be necessary in DL.
>
> My running firewall.rules ONLY probes "ipt_LOG", and it works fine.
> When I do a lsmod on my DL firewall (pre 0.6), I get all of these:
>
> ipt_TOS 1048 3 (autoclean)
> iptable_mangle 2168 1 (autoclean)
> ipt_REJECT 3192 1 (autoclean)
> ipt_state 568 7 (autoclean)
> ipt_MASQUERADE 1368 1 (autoclean)
> iptable_nat 17464 1 (autoclean) [ipt_MASQUERADE]
> ip_conntrack 19360 2 (autoclean) [ipt_state ipt_MASQUERADE
> iptable_nat]
> iptable_filter 1740 1 (autoclean)
> ipt_LOG 3384 4
> ip_tables 12152 10 [ipt_TOS iptable_mangle ipt_REJECT
> ipt_state ipt_MASQUERADE iptable_nat iptable_filter ipt_LOG]
So where are the ftp modules?
>
> So it appears they get loaded automatically, or some other script is
> loading them. (I think it's automatic because of the "autoclean")
The ftp modules will not get loaded automatically, so active ftp will
not work, just passive ftp.
There are also some other modules, eg. for IRC, ....
see /lib/modules/KERNEL-VERSION/kernel/net/ipv4/netfilter
--
MfG / Regards
Friedrich Lobenstock
____________________________________________________________________
Friedrich Lobenstock Linux Services Lobenstock
URL: http://www.lsl.at/ Email: fl...@fl...
____________________________________________________________________
|