an iptables on a Fedora box
글쓴이: atie / 작성시간: 수, 2004/03/10 - 12:53오전
Fedora에서 samba, phpBB2(w/ mySQL) 그리고 vnc를 허용하는 iptables (/etc/sysconfig/iptables) 설정입니다.
Quote:
# Firewall configuration written by redhat-config-securitylevel
# Manual customization of this file is not recommended.
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:RH-Firewall-1-INPUT - [0:0]
-A INPUT -j RH-Firewall-1-INPUT
-A FORWARD -j RH-Firewall-1-INPUT
#accept everything from localhost to localhost
-A RH-Firewall-1-INPUT -p all -s localhost -d localhost -j ACCEPT
-A RH-Firewall-1-INPUT -p all -s localhost.localdomain -d localhost.localdomain -j ACCEPT
-A RH-Firewall-1-INPUT -i lo -j ACCEPT
-A RH-Firewall-1-INPUT -p icmp --icmp-type any -j ACCEPT
-A RH-Firewall-1-INPUT -p 50 -j ACCEPT
-A RH-Firewall-1-INPUT -p 51 -j ACCEPT
-A RH-Firewall-1-INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT
#accept 137:138 - netbios-ns:dgm
-A RH-Firewall-1-INPUT -p udp -m udp --dport 137:138 -j ACCEPT
-A RH-Firewall-1-INPUT -p udp -m udp --sport 137:138 -j ACCEPT
#accept 139 - netbios-ssn
-A RH-Firewall-1-INPUT -p tcp -m tcp --dport 139 -j ACCEPT
#accept 445 - microsoft-ds
-A RH-Firewall-1-INPUT -p tcp -m tcp --dport 445 -j ACCEPT
-A RH-Firewall-1-INPUT -p udp -m udp --dport 445 -j ACCEPT
#accept 1512 - wins
-A RH-Firewall-1-INPUT -p tcp -m tcp --dport 1512 -j ACCEPT
-A RH-Firewall-1-INPUT -p udp -m udp --dport 1512 -j ACCEPT
#Open 5901 to allow vnc
-A RH-Firewall-1-INPUT -m state --state NEW -m tcp -p tcp --dport 5901 -j ACCEPT
-A RH-Firewall-1-INPUT -j REJECT --reject-with icmp-host-prohibited
#block mysql (tcp 3306)
-A INPUT -p tcp --destination-port 3306 -j DROP
COMMIT
이 밖에 필요한 내용을 덧붙여 모두를 위한 참조를 만들어 보면 어떨까요? 예를 들어, 내부 (172.x.x) 에서 오는 접속은 허용하고 외부에서의 모든 접속은 거부하는 설정을 한다던지 해서요.
Forums:
댓글 달기