Re: [arch-general] iptables not working well?
On Sun, Jul 10, 2011 at 5:02 PM, Dr. Robert Marmorstein <robert@narnia.homeunix.com> wrote:
It's workin like I showed on a debian box. But I'll try of course.
ppp0 is my connection to the external world (ISP through PPPoE), so the idea is not to accept new connections from the outside. That seemed logical to me. And has been working on the debian box for quiet a while. However I'll remove conditional acceptance, just plain accept new connections both from inside as from outside.
I'll experiment a bit with your settings, I hope you're right, :-) Notice that even though my setting look a bit dated, they're still working for me on an old debian box (which I'm trying to replace)...
In terms of security stuff, I strongly recommend you think about adding some limit matches -- at least for SSH and HTTP ports if you have them open.
Yes, I haven't set a firewall, just a transparent gateway, I mean a plane router between my ISP and my internal LAN. So far I don't have any service, like web or mail, so it hadn't been much of a constrain, but I can learn how to do things and implement them. Perhaps you can share later on more on your suggestions for more security, :-)
Hope this helps,
Yeap, I'll try, and then will let you and the list know...
Robert
Thanks a lot, -- Javier.
I don't see the previous message in my mailbox, but… he is wrong. The correct way is -o ppp0, you want to MASQUERADE everything that goes out of your internet facing interface. -- damjan
participants (2)
-
Damjan Georgievski
-
Javier Vasquez