iptables Rules for my network | Unix Linux Forums | Red Hat

  Go Back    


Red Hat Red Hat is the world's leading open source technology solutions provider with offerings including Red Hat Enterprise Linux (RHEL), Fedora, open source applications, security and systems management, virtualization, and Services Oriented Architecture (SOA) solutions.

iptables Rules for my network

Red Hat


Closed Thread    
 
Thread Tools Search this Thread Display Modes
    #1  
Old 03-26-2013
Vaibhav.T Vaibhav.T is offline
Registered User
 
Join Date: Dec 2011
Last Activity: 29 July 2013, 1:20 PM EDT
Posts: 28
Thanks: 6
Thanked 0 Times in 0 Posts
RedHat iptables Rules for my network

Hi Champs

i am new in Iptables and trying to write rules for my Samba server.I took some help from internet, created one script and run from rc.local :

#Allow loopback

iptables -I INPUT -i lo -j ACCEPT

# Accept packets from Trusted network

iptables -A INPUT -s my-network/subnet -j ACCEPT

# to allow established session to received traffic

iptables -A INPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT

# to allow SSH on port 22 from my network

iptables -A INPUT -i eth0 -p tcp -s my-network/subnet --dport 22 -m state --state NEW,ESTABLISHED -j ACCEPT
iptables -A OUTPUT -o eth0 -p tcp --sport 22 -m state --state ESTABLISHED -j ACCEPT

# To Allow incoming traffice on default SAMBA PORTS

iptables -A INPUT -p udp --dport 137 -j ACCEPT
iptables -A INPUT -p udp --dport 138 -j ACCEPT
iptables -A INPUT -p udp --dport 139 -j ACCEPT
iptables -A INPUT -p tcp --dport 139 -j ACCEPT
iptables -A INPUT -p tcp --dport 445 -j ACCEPT

#Enable Logging

iptables -A INPUT -j LOG
iptables -A INPUT -m limit --limit 2/min -j LOG --log-prefix "Iptables packet Drop" --log-level 7

# Drop all other Packets

iptables -A INPUT -j DROP

I also created one separate log file for iptables in /var/log/iptables.log and edit /etc/syslog.conf :

*.info;kern!=warning;mail.none;news.none;authpriv.none;cron.none /var/log/message

# Add new location

kern.warning /var/log/iptables.log


But my Drop packets are not showing in iptables.log file.Please let me know if i am doing wrong and let me know the correct way to write.I only want samba communication and SSH nothing else.

Thank You

Vaibhav

Last edited by Vaibhav.T; 03-26-2013 at 07:06 PM..
Sponsored Links
Closed Thread

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
Iptables/Firewall rules for multicast IP. rama krishna Red Hat 0 08-29-2012 04:16 PM
iptables rules (ubuntu) Greenice Ubuntu 0 02-11-2012 04:55 AM
Editing rules on iptables garric Security 4 09-13-2011 05:22 PM
Iptables rules at boot solaris_user IP Networking 2 01-06-2010 06:49 PM
SED inserting iptables rules in while loop verbalicious Shell Programming and Scripting 2 12-22-2009 11:12 AM



All times are GMT -4. The time now is 12:26 PM.