Tags » Iptables

IPTables Rules

IPTables Rules Commands :
-----------------------


IPTABLES TO REJECT ALL OUTGOING NETWORK CONNECTIONS :
---------------------------------------------------
iptables -F OUTPUT
iptables -A OUTPUT -m state \ --state ESTABLISHED -j ACCEPT
iptables -A OUTPUT -j REJECT


IPTABLES TO REJECT ALL INCOMING NETWORK CONNECTIOS :
--------------------------------------------------
iptables -F INPUT
iptables -A INPUT -m state \ --state ESTABLISHED -j ACCEPT
iptables -A INPUT -j REJECT


IPTABLES TO REJECT ALL NETWORK CONNECTIONS :
------------------------------------------
iptables -F
iptables -A INPUT -j REJECT
iptables -A OUTPUT -j REJECT
iptables -A FORWARD -j REJECT


IPTABLES TO DROP INCOMING PING REQUSTS :
--------------------------------------
iptables -A INPUT -p icmp --icmp-type echo-request -j DROP


IPTABLES TO DROP OUTGOING TELNET CONNECTIONS :
--------------------------------------------
iptables -A OUTPUT -p tcp --dport telnet -j REJECT


IPTABLES TO DROP INCOMING TELNET CONNECTIONS :
--------------------------------------------
iptables -A INPUT -p tcp --dport telnet -j REJECT


IPTABLES TO REJECT OUTGOING SSH CONNECTIONS :
-------------------------------------------
iptables -A OUTPUT -p tcp --dport ssh -j REJECT


IPTABLES TO REJECT INCOMING SSH CONNECTIONS :
-------------------------------------------
iptables -A INPUT -p tcp --dport ssh -j REJECT


IPTABLES TO REJECT ALL INCOMING TRAFFIC EXCEPT SSH & LOCAL CONNECTIONS :
----------------------------------------------------------------------
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -p tcp --dport ssh -j ACCEPT
iptables -A INPUT -j REJECT


IPTABLES TO ACCEPT INCOMING SSH CONNECTIONS FROM SPECIFIC IP ADDRESS :
--------------------------------------------------------------------
iptables -A INPUT -p tcp -s IPADDRESS --dport ssh -j ACCEPT
iptables -A INPUT -p tcp --dport ssh -j REJECT


IPTABLES TO ACCEPT INCOMING SSH CONNECTIONS FROM SPECIFIC MAC ADDRESS :
---------------------------------------------------------------------
iptables -A INPUT -m mac --mac-source MAC-ADDRESS -p tcp --dport ssh -j ACCEPT
iptables -A INPUT -p tcp --dport ssh -j REJECT


IPTABLES TO REJECT INCOMING CONNECTIONS ON A SPECIFIC TCP PORT :
--------------------------------------------------------------
iptables -A INPUT -p tcp --dport TCP-PORT -j REJECT


IPTABLES TO DROP ALL INCOMING CONNECTIONS ON A SPECIFIC NETWORK INTERFACE :
-------------------------------------------------------------------------
iptables -A INPUT -i eth0 -s 192.168.0.0/16 -j DROP


IPTABLES TO CREATE A SIMPLE IP MASQUERADING :
-------------------------------------------
echo "1" > /proc/sys/net/ipv4/ip_forward
iptables -t nat -A POSTROUTING -o $EXT_IFACE -j MASQUERADE


REJECT ALL INCOMING TELNET EXCEPT SPECIFIED IPADDRESS :
-----------------------------------------------------
iptables -A INPUT -t filter ! 71 more words
IPTables

Docker pitfalls for Internet-facing hosts

Planning to use Docker on an unprotected Internet-facing host? If so, don’t rush it. It works, but the default installation is probably not what you want. 104 more words

Linux

How to Harden IPTABLES in your Ubuntu/debian Server

Hi

Today I’ll post a simple Iptables configuration , to harden a server connection , before apply any of this changes remember that if  your server brings X services , this configuration will close the server to 2 operating ports… 337 more words

Misc

Port Knocking Menggunakan Enkripsi Diffie Hellman dan RC4 dengan Cryptknock

1. Kata Pengantar
Cryptknock adalah aplikasi port knocking yang terenkripsi. Tidak seperti port knocking lain yang menggunakan port TCP atau informasi protokol lain untuk sinyal ketukan, string terenkripsi digunakan sebagai ketukan. 237 more words

IT Security

Firewall or not: How to read Linda Ikeji blog and other blocked sites in a corporate organization

Me: Forgive me, Father for I have sinned. It’s been 30 days since my last confession.  These are my sins: I did a “pretty bad thing” today. 157 more words

A script to add the three big Finnish operators' IP networks to iptables

This script will output RHEL compatible /etc/sysconfig/iptables lines.
It will list the autonomous system numbers for the three biggest Finnish operators.

Sonera = AS1759
Elisa = AS719, AS790, AS6667, AS34188, AS21366, AS20931… 110 more words

Linux iptables part II: IPv6 and NAT

After the basics in part I, on to IPv6 and NAT. The title is misleading here: iptables exists for IPv6 and iptables can do NAT, but iptables cannot do NAT for IPv6 connections. 708 more words

Security