[Last Call] Learn about multicloud storage options and how to improve your company's cloud strategy. Register Now

x
?
Solved

iptables Question - Default policy

Posted on 2006-11-08
2
Medium Priority
?
159 Views
Last Modified: 2012-05-05
Using the example below, all incoming packets are automatically dropped (ie ignored) for the workstation unless
-The packets are for udp ports 137 through 139 and originate from an IP address of 66.66.66.66
-The packets are for tcp port 445 and originate from an IP address of 66.66.66.66.  
-The packets are used for loopback

Am I interpreting this correctly?  

What is the established/related entry useful for?

iptables -P INPUT DROP
iptables -P OUTPUT ACCEPT
iptables -P FORWARD DROP
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -i eth0 -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -i eth0 -p udp -m udp -s 66.66.66.66 --dport 137:139 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp - m tcp -s 66.66.66.66 --dport 445 -j ACCEPT
0
Comment
Question by:BendOverIGotYourBack
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 43

Accepted Solution

by:
ravenpl earned 500 total points
ID: 17904654
You are correct.
> iptables -A INPUT -i eth0 -m state --state ESTABLISHED,RELATED -j ACCEPT
In short it means to accept packets that comes within already started connections(ESTABLISHED) - usually those are connections initiated from the box itself - in other words all outgoing connaections are permitted(since iptables -P OUTPUT ACCEPT)
Also RELATED connections are fine. There are some cases, where connecting to Your host requires two connections. A good examples are ftp and auth protocols.
0
 

Author Comment

by:BendOverIGotYourBack
ID: 17942124
thank you.
0

Featured Post

How to Use the Help Bell

Need to boost the visibility of your question for solutions? Use the Experts Exchange Help Bell to confirm priority levels and contact subject-matter experts for question attention.  Check out this how-to article for more information.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

​Being a Managed Services Provider (MSP) has presented you  with challenges in the past— and by meeting those challenges you’ve reaped the rewards of success.  In 2014, challenges and rewards remain; but as the Internet and business environment evol…
Fine Tune your automatic Updates for Ubuntu / Debian
In this video you will find out how to export Office 365 mailboxes using the built in eDiscovery tool. Bear in mind that although this method might be useful in some cases, using PST files as Office 365 backup is troublesome in a long run (more on t…
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…

650 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question