Help with good and simple 'iptables' examples...

Help with good and simple 'iptables' examples...

Post by JeffKosow.. » Wed, 06 Nov 2002 13:50:28



I am trying to set up iptables on my RH8.0 (kernel 2.4.18) distro.

I have found that the built-in lokkit configurator is way too
simplistic. i.e. it leaves out basic services like samba, ntp, real
audio, etc.

On the other hand, many of the examples on the net appear to be way
too complicated.

---

My situation is as follows:

Small home network with a couple of Linux machines and a couple of
Windoze machines (Win98, WinXP, Win2k).

I believe I need to allow the following services:

ntp (for setting network time)
samba (for mounting disks on mywindoze machines)
nfs (for mounting disks on my other linux machines)
http (for my small apache server)
ssh (for communicating between computers and for logging in from work)
dhcp??? (I use a mix of static and dynamic addresses set up by my
        linksys router)
realaudio (and presumably other streaming formats?)
icq chat
virus program updates (I use f-prot)

Does anybody have a simple documented example that addresses these
basic services?
I am looking for something that I can understand and then build upon.

Thanks,
Jeff

 
 
 

Help with good and simple 'iptables' examples...

Post by JeffKosow.. » Wed, 06 Nov 2002 13:53:31


I am trying to set up iptables on my RH8.0 (kernel 2.4.18) distro.

I have found that the built-in lokkit configurator is way too
simplistic. i.e. it leaves out basic services like samba, ntp, real
audio, etc.

On the other hand, many of the examples on the net appear to be way
too complicated.

---

My situation is as follows:

Small home network with a couple of Linux machines and a couple of
Windoze machines (Win98, WinXP, Win2k).

I believe I need to allow the following services:

ntp (for setting network time)
samba (for mounting disks on mywindoze machines)
nfs (for mounting disks on my other linux machines)
http (for my small apache server)
ssh (for communicating between computers and for logging in from work)
dhcp??? (I use a mix of static and dynamic addresses set up by my
        linksys router)
realaudio (and presumably other streaming formats?)
icq chat
virus program updates (I use f-prot)

Does anybody have a simple documented example that addresses these
basic services?
I am looking for something that I can understand and then build upon.

Thanks,
Jeff

 
 
 

Help with good and simple 'iptables' examples...

Post by Robert Lync » Wed, 06 Nov 2002 14:03:43



> I am trying to set up iptables on my RH8.0 (kernel 2.4.18) distro.

> I have found that the built-in lokkit configurator is way too
> simplistic. i.e. it leaves out basic services like samba, ntp, real
> audio, etc.

> On the other hand, many of the examples on the net appear to be way
> too complicated.

> ---

> My situation is as follows:

> Small home network with a couple of Linux machines and a couple of
> Windoze machines (Win98, WinXP, Win2k).

> I believe I need to allow the following services:

> ntp (for setting network time)
> samba (for mounting disks on mywindoze machines)
> nfs (for mounting disks on my other linux machines)
> http (for my small apache server)
> ssh (for communicating between computers and for logging in
> from work)
> dhcp??? (I use a mix of static and dynamic addresses set up by my
>         linksys router)
> realaudio (and presumably other streaming formats?)
> icq chat
> virus program updates (I use f-prot)

> Does anybody have a simple documented example that addresses these
> basic services?
> I am looking for something that I can understand and then build
> upon.

> Thanks,
> Jeff

What about starting from here:

5. Rusty's Really Quick Guide To Packet Filtering

http://www.netfilter.org/unreliable-guides/packet-filtering-HOWTO/pac...

This is basically how I initially set up my firewall. To which I
added logging, etc. as needed.

HTH. Bob L.
--

 
 
 

Help with good and simple 'iptables' examples...

Post by alex » Wed, 06 Nov 2002 22:26:36



Quote:> I am looking for something that I can understand and then build upon.

I found this useful:
http://www-106.ibm.com/developerworks/security/library/s-netip/

alexd

--
http://www.troffasky.pwp.blueyonder.co.uk/pix/
AIM:troffasky
Knives and guns are dangerous,
They don't want to play with us

 
 
 

Help with good and simple 'iptables' examples...

Post by mjt » Thu, 07 Nov 2002 04:18:15



> I am trying to set up iptables on my RH8.0

.... it is good netiquette to CANCEL a duplicate posting.

--
-------------------------------------------+---------------------------
 Michael J. Tobler: motorcyclist, surfer,  |    Black holes result
 skydiver, and author: "Inside Linux",     |   when God divides the  
 "C++ HowTo", "C++ Unleashed"              |     universe by zero

 
 
 

Help with good and simple 'iptables' examples...

Post by Jeffrey J. Kosows » Fri, 08 Nov 2002 04:01:10




> > I am trying to set up iptables on my RH8.0

> .... it is good netiquette to CANCEL a duplicate posting.

.... and it is also good netiquette not to assume the worse about
people.

I had a duplicate posting because I was having problem with my
newsreader and server. As a result it double posted and then
subsequently I was *NOT* able to cancel because it doesn't think I am
the owner...

 
 
 

Help with good and simple 'iptables' examples...

Post by mjt » Fri, 08 Nov 2002 04:14:43



> subsequently I was NOT able to cancel because it doesn't think I am
> the owner...

.... "what" thinks you're not the owner - your newsreader? if so,
then your Gnus is broken :)   (i've always been able to
cancel or supercede my articles).

--
-------------------------------------------+---------------------------
 Michael J. Tobler: motorcyclist, surfer,  |    Black holes result
 skydiver, and author: "Inside Linux",     |   when God divides the  
 "C++ HowTo", "C++ Unleashed"              |     universe by zero

 
 
 

1. Isn't There a Simple Example of PTY's?

I am trying to design an C++ streambuf subclass for use with a
subprocess via a pseudo terminal.

I have been looking around for a simple example or basic instructions
for using PTY's.  I have found in the archives of comp.sources.unix
the "pty" program, but it is so huge and complicated that I can't pull
out the basic setup of the pty that I need.

Is there anywhere I can go to find a more basic implementation?

Thanks,
--
Robert Duff

Alcatel Network Systems
(214) 996-6964
============================================================
This file has nothing to do with Alcatel!

2. BASH Frequently-Asked Questions (FAQ version 3.6)

3. Simple 'sed', 'awk', 'cut' problem

4. Problem with adaptec 2940 or one of the SCSI devices

5. ??: 'bootpd' and '/etc/bootptab' Examples?

6. realplayer 7 problem

7. iptables v1.2.2: can't initialize iptables table `filter': Table does not exist

8. Red Hat 7.0 Backspace not working in Gnome.

9. iptables "can't initialize iptables table `filter'"

10. IPTables vs. DNS (or : iptables doesn't change sourceport when MASQ'ing)

11. iptables v1.2.2: can't initialize iptables table `filter': Table does not exist

12. simple example of an ldapsearch if you don't know ldap setup?

13. help on example in 'man libipq'