Results 1 to 3 of 3

Thread: iptables configuration

Hybrid View

  1. #1

    iptables configuration

    I have a new question about iptables.

    I have a router/internet gateway that has several different networks connected to it. There is 192.168.1.0/24, 192.168.2.0/24 and 192.168.3.0/24. The 192.168.2.0/24 network has a branch router of 192.168.2.30 that is connected to a 192.168.10.0/24 network. I would like to block access of the 192.168.10.0 network to the 192.168.1.0 network. What type of iptables command would I use on my gateway/router to do this?

    Something like this:

    iptables -A INPUT -s 192.168.2.30 -i eth2 -p all -d 192.168.1.0/24 -j DROP

  2. #2
    Administrator Associate gr8rcake's Avatar
    Join Date
    May 2004
    Posts
    44
    As the traffic isn't destined for the firewall the INPUT isn't correct, it should be FORWARD instead. FORWARD is used for routing traffic through the firewall.

    Code:
    iptables -A FORWARD -s 192.168.10.0/24 -i eth2 -p all -d 192.168.1.0/24 -j DROP
    The traffic isn't coming from the 192.168.2.30 router IP address, but the 192.168.10.0/24 network, so there should be no reference to 192.168.2.30. Unless NAT is involved, routers / firewalls do not change the source / destination IP address of the packets.

    To simplify the rule you could also delete the reference to the interfaces.

    Code:
    iptables -A FORWARD -s 192.168.10.0/24 -p all -d 192.168.1.0/24 -j DROP
    You should also consider logging dropped packets to make troubleshooting easier.

    Hope this helps.

  3. #3
    That worked perfectly.....thanks.

Similar Threads

  1. VNC Configuration
    By udhay in forum Redhat / Fedora
    Replies: 1
    Last Post: 04-19-2012, 06:26 AM
  2. DNS Configuration
    By mrjrt in forum Linux - Hardware, Networking & Security
    Replies: 6
    Last Post: 02-03-2010, 10:39 PM
  3. YUM configuration
    By pawnbeeta in forum Linux - Software, Applications & Programming
    Replies: 1
    Last Post: 01-20-2008, 06:20 PM
  4. iptables configuration for BIND
    By bkesting in forum Security
    Replies: 3
    Last Post: 01-27-2006, 02:21 PM
  5. IDE slot configuration?
    By Bartman in forum Linux - Hardware, Networking & Security
    Replies: 2
    Last Post: 09-06-2002, 12:38 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •