Solved

Simple question: closing ports

Posted on 2001-08-11
6
328 Views
Last Modified: 2010-03-18
I want to close off some ports on my machine and I was told to use iptables (I have kernel 2.4.3). I can't figure out how to do it from the man page. What command would I issue to say close off port 111?
0
Comment
Question by:deck16
6 Comments
 
LVL 51

Accepted Solution

by:
ahoffmann earned 75 total points
ID: 6377085
iptables -A FORWARD -d <your-IP> --dport 111 -j DROP
iptables -A INPUT   -d localhost --dport 111 -j DROP

# you need to have packetfiltering enabled in the kernel
0
 
LVL 1

Expert Comment

by:zxcvzxcv
ID: 6377902
you put a place to put my IP. I don't have a static IP. What do I put there? (localhost?)
0
 

Author Comment

by:deck16
ID: 6377910
rrr, I hate the auto-login (sorry for posting with a different account I'm at by brother's house (zxcvzxcv) not used to having to logout and then back in :-)
0
Master Your Team's Linux and Cloud Stack!

The average business loses $13.5M per year to ineffective training (per 1,000 employees). Keep ahead of the competition and combine in-person quality with online cost and flexibility by training with Linux Academy.

 
LVL 7

Expert Comment

by:HalldorG
ID: 6378010
What about

ADDR=$(/sbin/ifconfig ppp0 | grep addr | cut -d':' -f 2 | cut -d' ' -f 1)

There the address is set as it IP number of your machine
and later refer to the IP address as $ADDR

Like


iptables -A FORWARD -d $ADDR/32 --dport 111 -j DROP




0
 

Author Comment

by:deck16
ID: 6378415
why $ADDR/32 in the iptables argument?
0
 
LVL 7

Expert Comment

by:HalldorG
ID: 6381665
that is the mask for the address 32 bits = 255.255.255.255
0

Featured Post

Flexible connectivity for any environment

The KE6900 series can extend and deploy computers with high definition displays across multiple stations in a variety of applications that suit any environment. Expand computer use to stations across multiple rooms with dynamic access.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have seen several blogs and forum entries elsewhere state that because NTFS volumes do not support linux ownership or permissions, they cannot be used for anonymous ftp upload through the vsftpd program.   IT can be done and here's how to get i…
Note: for this to work properly you need to use a Cross-Over network cable. 1. Connect both servers S1 and S2 on the second network slots respectively. Note that you can use the 1st slots but usually these would be occupied by the Service Provide…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question