questions about ipfilter


 
Thread Tools Search this Thread
Special Forums Cybersecurity questions about ipfilter
# 1  
Old 11-16-2009
questions about ipfilter

Dears,
i am a new user for using ipfilter in solaris 10
and i have some question about this:
by using ipfilter
for example
1- i want specific MAC address able to access hotmail only
2- also i want to make 10MB for this MAC address is a max download per day
3- i am asking about using MAC address specific for reson

if i had in the same range some user i allow them to access www.hotmail.com and the rest of the user does not allow to access www.hotmail.com
what can i do for this Situation




ipfilter able to do that

thanks
MAX

Last edited by coxmanchester; 11-17-2009 at 09:27 AM..
Login or Register to Ask a Question

Previous Thread | Next Thread

9 More Discussions You Might Find Interesting

1. Solaris

A little help with ipfilter on Omnios

I'm on OmniOS. I have set a linux zone(lx zone) wich use 10.2.0.0/24 network. The other network,connected to internet is 192.168.0.0/24 The network interface of 10.2.0.0/24 is bge1 The network interface of 192.168.0.0/24 is bge0 I know is more easy to use the same network but i prefer to... (1 Reply)
Discussion started by: Linusolaradm1
1 Replies

2. Solaris

Ipfilter question

Howdy My goal is to block locally the applications on a Solaris 10 server to access specific port on a remote machine. All attempts to access the <remote ip>:<remote port> should be rejected with ICMP port unreachable or with TCP RST. I tried with the following: block... (2 Replies)
Discussion started by: ralome
2 Replies

3. Solaris

ipfilter blocking ip fragments

For some reason ipfilter is blocking inbound fragmented ip packets (the packets are larger than the interface's MTU) that are encapsulating UDP segments. The connection works, so I know ipfilter is letting some traffic through, it is just a lot slower than it should be. Rules that allow the... (3 Replies)
Discussion started by: ilikecows
3 Replies

4. Homework & Coursework Questions

Print questions from a questions folder in a sequential order

1.) I am to write scripts that will be phasetest folder in the home directory. 2.) The folder should have a set-up,phase and display files I have written a small script which i used to check for the existing users and their password. What I need help with: I have a set of questions in a... (19 Replies)
Discussion started by: moraks007
19 Replies

5. Solaris

NAT IPFilter

Hi everybody, I'm running on Solaris 10 X86 (update 1009). I would like to make NAT's rule. I explain you. On Solaris, I configure the principal interface e1000g0 with IP : 192.168.0.33 I created the first logical interface like that : ifconfig e1000g0 addif 192.168.0.40 netmask... (0 Replies)
Discussion started by: aureliensm
0 Replies

6. Solaris

Syntax error ipfilter solaris 10

Hello everyone. I have a problem with ipfilter, you must create a rule to redirect traffic from the external network to internal server on port 443. New Rule: rdr e1000g0 from xx.xx.xx.69/32 port 443 -> 192.168.10.5 port 443 tcp, use ipnat -CF -f /etc/ipnat.conf, and ipf send me from error:... (0 Replies)
Discussion started by: kadavr
0 Replies

7. Programming

two questions

hey all, I have question when am writing simple shell... in the child am calling execvp, i want the parent to know when execvp returns - 1. how can i let the parent know the result of execvp thanks in advance (9 Replies)
Discussion started by: joey
9 Replies

8. Solaris

ipfilter solaris express

Hello, | am trying to setup ipfilter on solaris express snv_91 but I don't seem to have the following file available. /etc/ipf/pfil.ap Is this an older way of configuring the interface?, I have all the packages installed. Thanks, (1 Reply)
Discussion started by: Actuator
1 Replies

9. HP-UX

ipfilter hpux11.11

how can I create a rule that will allow my machine to FTP to itself, but not allow other machines to FTP to it.. I know this sounds weird but this how they want it so they can test some application functionality that uses ftp. (2 Replies)
Discussion started by: csaunders
2 Replies
Login or Register to Ask a Question
NET(8)							      System Manager's Manual							    NET(8)

NAME
netscript - netscript network configuration command SYNOPSIS
netscript start|stop|reload|restart netscript ifup|ifdown|ifqos|ifreload <interface-name>|all netscript compile [ -fhq ] [ -b max-backup-level ] netscript ipfilter load|clear|fairq|flush|reload|save netscript ipfilter usebackup [ backup-number ] netscript ipfilter exec <function-name1>|<function-name2> [chain p1 p2 ...] netscript ip6filter load|clear|fairq|flush|reload|save netscript ip6filter usebackup [ backup-number ] netscript ip6filter exec <function-name1>|<function-name2> [chain p1 p2 ...] DESCRIPTION
This manual page documents briefly the netscript command from the netscript router/firewall network configuration package. This command is used to configure/reconfigure the interface configuration, ipchains filter setup, and ip route service ( QoS ) setup that are configured in netscript's configuration files. It can manipulate individual interfaces, and reconfigure the iptables filter contents and firewall setup, or reconfigure the QoS setup. It is rather incomplete as it does not describe fully the finely tuned manipulations that happen due to netscript's design which enables a Linux box to serve as a high availability heavy-duty mission-critcial network router or firewall. COMPILE CONFIGURATION MODE
The rules can be compiled and automatically loaded on boot by setting the IPV4_CONFIGURE_SWITCH switch in network.conf(5) to the value of the function used to configure the kernel. Net-compile(8) creates this function as 'Configure'. If this switch is set, the netscript startup will run netscript-compile(8) to make sure everything is up to date and load the rules from /etc/netscript/ipfil- ter-defs.conf, and the relevant settings in network.conf(5) which are used to establish packet grooming and configure the built in ker- nel netfilter INPUT and FORWARD chains in the filter table. If compilation fails, the previous rule set is not replaced and it is used instead. A similar mode exists for IPv6, but it is not fully implemented yet. IPTABLES CONFIGURATION MODE
This configuration mode corresponds to the old method of doing it using iptables-save(8) and iptables-restore(8). This is the default for operation, and occurs if the IPV4_CONFIGURE_SWITCH is not set in network.conf(5). This is the metoh still used by IPv6 as well. OPTIONS
start Set up networking configruation by loading ipcahins filters, setting up bridge, configuring interfaces and running any configured lower layer protocol daemons or commands. For use from a startup script. stop Shut everything down. For use from a startup script. reload Refresh the setup of netscript except for iptables from the configuration files in /etc/netscript restart|force-reload Stop everthing and then start everything again. For use from a startup script. ifup <interface-name>|all Bring interfaces(s) up by starting any protocol daemons, and configuring interfaces. ifdown <interface-name>|all Shutdown said interface(s) by doing reverse of ifdown. ifqos <interface-name>|all Reload QoS configuration for interface(s). ifreload <interface-name>|all Refresh the interface setup and implement any configuration changes. ifreset <interface-name>|all Shutdown and then restart interface(s), reloading configuration from lower layer up to the network layer. compile [ -fhq ] [ -b max-backup-level ] Compile the new definitions in /etc/netscript/ipfilter-defs directory into a new set of functions in the /etc/netscript/ipfilter- defs-compiled.conf file. See the netscript-compile(8) and ipfilter-defs(5) manpages for details. ipfilter load|reload Load/reload the IPv4 iptables filters and reconfigure the firewalling, from that saved in /etc/netscript/iptables (via iptables- restore(8) ), and the QoS fair queuing setup, or by excuting the requisite configuration function from /etc/netscript/ipfilter-defs- compiled.conf if using ipfilter-defs(5) mode. ipfilter save Save the IPv4 iptables configuration to /etc/netscript/iptables via iptables-save(8) , after backing it up to /etc/netscript/ipta- bles.1 and cycling the previous backup files down through the configuration history. This does not work if the IPv6 side of netscript is operating in ipfilter-defs(5) mode. ipfilter usebackup [ backup-number ] Restore setup from the IPv4 iptables backup configuration from /etc/netscript/iptables.n ( default 1 ) via iptables-restore(8), or if the ipfilter-defs(5) backend is used, the requisite backup number from the /etc/netscript/ipfilter-defs.conf history files. ipfilter clear|flush Remove iptables and any firewall setup, and if IPV4_FWDING_KERNEL is set to FILTER_ON (see network.conf(5) ), disables all IPv4 packet forwarding on the router. Very useful for debugging protocol problems on a firewall by enabling a reasonably safe check to be made with the filtering down. ipfilter forward|fwd Turns on the IPv4 kernel forwarding switch manually. This is irrespective of the setting of IPV4_FWDING_KERNEL (see network.conf(5) ). Use with caution as it will allow traffic through the box. ipfilter noforward|nofwd Turns off the IPv4 kernel forwarding switch manually. This is irrespective of the setting of IPV4_FWDING_KERNEL (see net- work.conf(5) ). Use with caution as it will cut off reachability. ipfilter fairq Reload the IPv4 fairq chain that marks the packets for the QoS interface transmit queues. ip6filter load|reload Load/reload the IPv6 iptables filters and reconfigure the firewalling, from that saved in /etc/netscript/ip6tables (via ip6tables-restore(8) ), and the QoS fair queuing setup, or by excuting the requisite configuration function from /etc/netscript/ipfilter-defs-compiled.conf if using ipfilter-defs(5) mode. ip6filter save Save the IPv6 iptables configuration to /etc/netscript/iptables via ip6tables-save(8) , after backing it up to /etc/netscript/ip6tables.1 and cycling the previous backup files down through the configuration history. This does not work if the IPv6 side of netscript is operating in ipfilter-defs(5) mode. ip6filter usebackup [ backup-number ] Restore setup from the IPv6 iptables backup configuration from /etc/netscript/ip6tables.n ( default 1 ) via ip6tables-restore(8), or if the ipfilter-defs(5) backend is used, the requisite backup number from the /etc/netscript/ipfilter-defs.conf history files. ip6filter clear|flush Remove IPv6 iptables setup, and if IPV6_FWDING_KERNEL is set to FILTER_ON (see network.conf(5) ), disables all IPv6 packet forward- ing on the router. Very useful for debugging protocol problems on a firewall by enabling a reasonably safe check to be made with the filtering down. ip6filter forward|fwd Turns on the IPv6 kernel forwarding switch manually. This is irrespective of the setting of IPV6_FWDING_KERNEL (see network.conf(5) ). Use with caution as it will allow traffic through the box. ip6filter noforward|nofwd Turns off the IPv6 kernel forwarding switch manually. This is irrespective of the setting of IPV6_FWDING_KERNEL (see net- work.conf(5) ). Use with caution as it will affect reachability. ip6filter fairq Reload the IPv6 fairq chain that marks the packets for the QoS interface transmit queues. FILES
/etc/netscript/if.conf, /etc/netscript/ipfilter.conf, /etc/netscript/network.conf, /etc/netscript/qos.conf, /etc/netscript/ipfilter-defs.conf, /etc/netscript/ipfilter-defs-compiled.conf, /etc/netscript/ipfilter-defs directory, /etc/netscript/iptables, /etc/netscript/ip6tables, /etc/netscript/ipfilter-defs-compiled SEE ALSO
netscript-compile(8), ipfilter-defs(5), if.conf(5), ipfilter.conf(5), network.conf(5), qos.conf(5), ip(8), tc(8), iptables(8), iptables- restore(8), iptables-save(8), ip6tables(8), ip6tables-restore(8), ip6tables-save(8), brcfg(8). AUTHOR
This manual page was written by Matthew Grant <grantma@anathoth.gen.nz>, for the Debian GNU/Linux system (but may be used by others). BUGS
I wrote this manpage when I was half asleep... January 24, 2003 NET(8)