?
Solved

iptables Question - Default policy

Posted on 2006-11-08
2
Medium Priority
?
158 Views
Last Modified: 2012-05-05
Using the example below, all incoming packets are automatically dropped (ie ignored) for the workstation unless
-The packets are for udp ports 137 through 139 and originate from an IP address of 66.66.66.66
-The packets are for tcp port 445 and originate from an IP address of 66.66.66.66.  
-The packets are used for loopback

Am I interpreting this correctly?  

What is the established/related entry useful for?

iptables -P INPUT DROP
iptables -P OUTPUT ACCEPT
iptables -P FORWARD DROP
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -i eth0 -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -i eth0 -p udp -m udp -s 66.66.66.66 --dport 137:139 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp - m tcp -s 66.66.66.66 --dport 445 -j ACCEPT
0
Comment
Question by:BendOverIGotYourBack
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 43

Accepted Solution

by:
ravenpl earned 500 total points
ID: 17904654
You are correct.
> iptables -A INPUT -i eth0 -m state --state ESTABLISHED,RELATED -j ACCEPT
In short it means to accept packets that comes within already started connections(ESTABLISHED) - usually those are connections initiated from the box itself - in other words all outgoing connaections are permitted(since iptables -P OUTPUT ACCEPT)
Also RELATED connections are fine. There are some cases, where connecting to Your host requires two connections. A good examples are ftp and auth protocols.
0
 

Author Comment

by:BendOverIGotYourBack
ID: 17942124
thank you.
0

Featured Post

Linux Academy Android App Now Supports Chromecast

We have some fantastic news for our Android fans. We’re so excited to announce that the Linux Academy Android app is now available with Chromecast support. That’s right – simply download the latest update of the Linux Academy App and start casting your favorite course videos!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Hello EE, Today we will learn how to send all your network traffic through Tor which is useful to get around censorship and being tracked all together to a certain degree. This article assumes you will be using Linux, have a minimal knowledge of …
Fine Tune your automatic Updates for Ubuntu / Debian
In this video you will find out how to export Office 365 mailboxes using the built in eDiscovery tool. Bear in mind that although this method might be useful in some cases, using PST files as Office 365 backup is troublesome in a long run (more on t…
Have you created a query with information for a calendar? ... and then, abra-cadabra, the calendar is done?! I am going to show you how to make that happen. Visualize your data!  ... really see it To use the code to create a calendar from a q…
Suggested Courses
Course of the Month11 days, 16 hours left to enroll

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question