06-04-2013
iptables On for eth0 and off for other interfaces
Hi all,
I am running a CentOS 6.4 box as an IDS and I need to configure one interface as the management interface which will require a firewall. However other ports (in promisc mode without IP) will have to be configured such that IPtables allows all traffic.
I need to achieve this by editing the /etc/sysconfig/iptables file.
So I want to keep all the existing inbound rules in there for some interfaces, but for other interfaces I need to allow all traffic in/out for IDS capture.
What is the best syntax to achieve this by fixed entries in /etc/sysconfig/iptables
Thanks,
Ll
10 More Discussions You Might Find Interesting
1. IP Networking
Hi there,
I got a problem with my linux eth0.
It worked well, just one day when i boot it, "Failed" to be active.
The eth0 is inactive! I tried to use KDE network configuration tool to add the type of the eth card, I can't make it active. It gave me warning of "the eth card can't be... (1 Reply)
Discussion started by: gusla
1 Replies
2. IP Networking
Hi there guys!
I have a small task that I have to accomplish, but I don't seem to be able to do that.
I have a server that I don't have physical access to, and I mostly control it with webmin. The server is running 2 websites. Both of these websites have their own domains that are linked to... (1 Reply)
Discussion started by: D-Lexy
1 Replies
3. Red Hat
when i finish installed rhel 4.4 to my hp dl585 box, ifcfg-eth0 and ifcfg-eth1 is not available.when i ifconfig -a,i can not see the eth0 and eth1, only lo0 and si0. Unlike to the other server i found eth0 and eth1 files in
/etc/sysconfig/network-scripts/.
what will i do? (2 Replies)
Discussion started by: kenshinhimura
2 Replies
4. Ubuntu
Greetings,
I have installed a Ubuntu server and attempting put a static IP address on interface ETH0. I edited the /etc/network/interfaces with the following:
auto eth0
iface eth0 inet static
address 192.168.203.270
gateway 192.168.203.1
netwask 255.255.255.0
network 192.168.0.0... (2 Replies)
Discussion started by: jroberson
2 Replies
5. UNIX for Dummies Questions & Answers
Hi,
Just installed Centos 5.1 on HP DL360, on this system I have to close to ten nic's. How can I find which one is eth0? When I do " ifconfig -a" I see all of them, but I can't tell which is eth0?
Please advice. (2 Replies)
Discussion started by: samnyc
2 Replies
6. Red Hat
Hi,
I have just installed RHEL 5.4 on a BL430c-class server and I am attempting to connect to the network only when I try and start eth0, I get the following error?
"Bringing up Interface eth0: hp device eth0 does not seem to be present, delaying initialization."
I am using a HP... (18 Replies)
Discussion started by: Duffs22
18 Replies
7. Red Hat
Hello,
I re-installed my laptop and installed a new copy of VMBOX, I created a VM Machine with my Rhel5 and a CEntos copy as well.
I am using a laptop HP DV4, I use wireless on the laptop.
Usually when I boot up in to either machine I would get eht0 and lo as usual now I just don't get... (4 Replies)
Discussion started by: NelsonC
4 Replies
8. Red Hat
Hi,
I have noticed some performance issues on my RHEL5 server but the memory and CPU utilization on the box is fine.
I have a 1G full duplexed eth0 card and I am suspicious that this may be causing the problem. My eth0 settings are as follows:
Settings for eth0:
Supported ports: ... (12 Replies)
Discussion started by: Duffs22
12 Replies
9. Solaris
Hi Al,
In course of understanding networking in Solaris, I have these doubts on Interfaces. Please clarify me. I have done fair research in this site and others but could not be clarified.
1. In the "ifconfig -a" command, I see many interfaces and their configurations. But I see many... (1 Reply)
Discussion started by: satish51392111
1 Replies
10. Red Hat
Hi guys,
I really need your help with this.
My network interface eth0 is up but not running. I checked udev rules and ifcfg-eth0 files to make sure the mac address are the same.
It just would not come up. Please please I will really appreciate the help here.
Thank you in advance. (3 Replies)
Discussion started by: cjashu
3 Replies
LEARN ABOUT XFREE86
iptables-apply
IPTABLES-APPLY(8) iptables 1.6.1 IPTABLES-APPLY(8)
NAME
iptables-apply - a safer way to update iptables remotely
SYNOPSIS
iptables-apply [-hV] [-t timeout] [-w savefile] {[rulesfile]|-c [runcmd]}
DESCRIPTION
iptables-apply will try to apply a new rulesfile (as output by iptables-save, read by iptables-restore) or run a command to configure
iptables and then prompt the user whether the changes are okay. If the new iptables rules cut the existing connection, the user will not be
able to answer affirmatively. In this case, the script rolls back to the previous working iptables rules after the timeout expires.
Successfully applied rules can also be written to savefile and later used to roll back to this state. This can be used to implement a store
last good configuration mechanism when experimenting with an iptables setup script: iptables-apply -w /etc/network/iptables.up.rules -c
/etc/network/iptables.up.run
When called as ip6tables-apply, the script will use ip6tables-save/-restore and IPv6 default values instead. Default value for rulesfile is
'/etc/network/iptables.up.rules'.
OPTIONS
-t seconds, --timeout seconds
Sets the timeout in seconds after which the script will roll back to the previous ruleset (default: 10).
-w savefile, --write savefile
Specify the savefile where successfully applied rules will be written to (default if empty string is given:
/etc/network/iptables.up.rules).
-c runcmd, --command runcmd
Run command runcmd to configure iptables instead of applying a rulesfile (default: /etc/network/iptables.up.run).
-h, --help
Display usage information.
-V, --version
Display version information.
SEE ALSO
iptables-restore(8), iptables-save(8), iptables(8).
LEGALESE
Original iptables-apply - Copyright 2006 Martin F. Krafft <madduck@madduck.net>. Version 1.1 - Copyright 2010 GW <gw.2010@tnode.com or
http://gw.tnode.com/>.
This manual page was written by Martin F. Krafft <madduck@madduck.net> and extended by GW <gw.2010@tnode.com or http://gw.tnode.com/>.
Permission is granted to copy, distribute and/or modify this document under the terms of the Artistic License 2.0.
iptables 1.6.1 IPTABLES-APPLY(8)