Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Alternative Computing > Linux Support
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Linux Support Linux - Operating Systems and Applications Support

Reply
 
LinkBack Thread Tools
Old 03-27-2006, 08:10 AM   #1 (permalink)
Registered User
 
Join Date: Mar 2006
Posts: 1
OS: Debian


iptables bridging firewall

Hello,

I am running Debian Sarge with kernel 2.6.9 and have set up a bridge between eth2 (inet) & eth1 (lan) using the bridge-tools package.

I am trying to use iptables to limit the number of outbound ICMP connections initiated from within the bridged network while allowing all inbound traffic to continue to pass through.

I modified slightly the honeynet projects rc.firewall and have got:

iptables -A FORWARD -p icmp -m physdev --physdev-out eth2 -m state --state NEW -m limit --limit 10/hour --limit-burst 10 -s 192.168.1.10 -j ACCEPT
iptables -A FORWARD -m physdev --physdev-in eth2 -d 192.168.1.10 -j ACCEPT
iptables -A FORWARD -m physdev --physdev-out eth2 -j DROP

Using the above rules I can ping the router from inside the bridge ten times before it begins to timeout, which is perfect. The problem comes when I try and ping from outside of the bridge in, all pings come back Request Timed Out regardless of wether the limit has been met.

How do I allow all incoming connections while blocking outgoing ones?

Help would be greatly appreciated.

SuperTimmy
SuperTimmy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 04-01-2006, 10:53 PM   #2 (permalink)
Asst. Manager, Alternative Computing Forums
 
batty_professor's Avatar
 
Join Date: Jul 2004
Location: Hooterville Il 45 mi. east of St. Louis mo
Posts: 2,608
OS: Fedora Core 5 for now


Send a message via AIM to batty_professor Send a message via MSN to batty_professor Send a message via Yahoo to batty_professor
The firewall should have a block for ping returns. If the block is on it will do as you see. The system may be working as you expect, but be blocking the ping returns. The ping block only stops incoming ping requests. I may be wrong too. but I would look for this.
__________________
It's better to know me and not need me than to need me and not know me. B.

While users are never under any obligation, if you feel the urge please feel free to visit our donation page. Every little bit helps.
And we thank you for your support.

Microsoft free Registered Linux user 397458
batty_professor is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 08:52 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85