Solved

iptables rules per user or application

Posted on 2009-07-10
1
1,201 Views
Last Modified: 2013-11-16
I want to script some iptables rules only for a specific application like a personal firewall on windows, but the iptables module is not working on multicore CPUs.

Is there another way?

Commands like the following are not working on SMP systems:
iptables -A OUTPUT -m owner --uid-owner 315 -m state --state NEW -j ACCEPT
 

iptables -A OUTPUT -m owner --uid-owner 315 --cmd-owner firefox -p tcp -m multiport \

--dport 80,443 -m state --state NEW -j ACCEPT

Open in new window

0
Comment
Question by:D-CPA
1 Comment
 
LVL 27

Accepted Solution

by:
Nopius earned 250 total points
ID: 24823464
> Is there another way?

Probably yes, but not with iptables and not with such control grain as with IPtables. You can try to use SELinux network acl features.
http://selinux-symposium.org/2005/presentations/session2/2-2-morris.pdf

Don't ask me, I never tested it :-)
0

Featured Post

New! My Passport Wireless Pro Wi-Fi Mobile Storage

Portable wireless storage to offload, edit, and stream anywhere.

High-capacity, wireless mobile storage designed to accompany professional photographers and videographers in the field to easily offload, edit and stream captured photos and high-definition videos.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Wikipedia defines 'Script Kiddies' in this informal way: "In hacker culture, a script kiddie, occasionally script bunny, skiddie, script kitty, script-running juvenile (SRJ), or similar, is a derogatory term used to describe those who use scripts or…
If you are like regular user of computer nowadays, a good bet that your home computer is on right now, all exposed to world of Internet to be exploited by somebody you do not know and you never will. Internet security issues has been getting worse d…
This tutorial demonstrates a quick way of adding group price to multiple Magento products.
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

919 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now