Difference between revisions of "Iptables"
From Teknologisk videncenter
m |
m (→Using IPTABLES) |
||
Line 4: | Line 4: | ||
Iptables is a commandline command with numerous options, and need some training to master. | Iptables is a commandline command with numerous options, and need some training to master. | ||
There are three tables you can use filter(default) [[NAT_Linux|nat]] and mangle. Only filter and [[NAT_Linux|nat]] shown below. | There are three tables you can use filter(default) [[NAT_Linux|nat]] and mangle. Only filter and [[NAT_Linux|nat]] shown below. | ||
− | [[Image:Iptables chains.png| | + | [[Image:Iptables chains.png|400px|thumb|left|iptables flowchart showing chains]] |
=== The filter chains === | === The filter chains === | ||
Basically [[iptables]] has three filters/chains | Basically [[iptables]] has three filters/chains | ||
Line 39: | Line 39: | ||
target prot opt source destination | target prot opt source destination | ||
</pre> | </pre> | ||
+ | |||
== IPTABLES firewall solutions == | == IPTABLES firewall solutions == | ||
*Shorewall firewall [http://www.shorewall.net/ Shorewall.net 9 | *Shorewall firewall [http://www.shorewall.net/ Shorewall.net 9 | ||
[[Category:Linux]] | [[Category:Linux]] |
Revision as of 15:39, 7 March 2009
iptables is a packet filtering, NAT/PAT and packet mangling tool for Linux. Used by a variety of Linux distributions including Ubuntu, Redhat and CentOS. Iptables is highly configurable and are used in many firewall solutions.
Using IPTABLES
Iptables is a commandline command with numerous options, and need some training to master. There are three tables you can use filter(default) nat and mangle. Only filter and nat shown below.
The filter chains
Basically iptables has three filters/chains
- INPUT : Packets from a Interface to a local process on the machine. A packet from outside to the machine.
- FORWARD: Packets traversing from one Interface to another Interface
- OUTPUT : Packets from a local process - the machine itself - to the outside world.
See the tables with the command
[root@bkshost sysconfig]# iptables -L Chain INPUT (policy ACCEPT) target prot opt source destination Chain FORWARD (policy ACCEPT) target prot opt source destination Chain OUTPUT (policy ACCEPT) target prot opt source destination
The nat chains
When you use the nat table or mangle tables
- PREROUTING : Incoming packets before Routing decision. Used fx. for Destination nat
- POSTROUTING: Incoming packets after Routing decision. Used fx. for Source nat
- OUTPUT : Packets from a local process - the machine itself - to the outside world.
See the tables with the command
[root@bkshost sysconfig]# iptables -L -t nat Chain PREROUTING (policy ACCEPT) target prot opt source destination Chain POSTROUTING (policy ACCEPT) target prot opt source destination Chain OUTPUT (policy ACCEPT) target prot opt source destination
IPTABLES firewall solutions
- Shorewall firewall [http://www.shorewall.net/ Shorewall.net 9