iptables persistent simple firewall
Instalacia balika:
apt install iptables-persistent
pravidla su v zlozke /etc/iptables/rules.v{4,6}
Pravidla pre IPv4 su v zlozke:
/etc/iptables/rules.v4
Predvoelen pravidla su:
# Generated by xtables-save v1.8.2 on Thu Jun 18 15:11:04 2020
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
COMMIT
# Completed on Thu Jun 18 15:11:04 2020
Tito pravidla je potrebne nahradit:
# Generated by xtables-save v1.8.2 on Thu Jun 18 13:14:47 2020
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [0:0]
# povol nadviazane spojenia ktore vyokonava server
-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
# povole localhost
-A INPUT -s 127.0.0.0/8 -j ACCEPT
#Povolenie sam na seba kvoli proxy
-A INPUT -s 192.168.3.31 -d 192.168.3.31 -j ACCEPT
#Povolenie portov
# UDP
-A INPUT -s 192.168.3.179 -p udp --dport 6514 -j ACCEPT
# tcp
-A INPUT -s 192.168.3.179 -p tcp --dport 6514 -j ACCEPT
#Povolenie IP rnge
-A INPUT -s 192.168.3.0/24 -j ACCEPT
COMMIT
# Completed on Thu Jun 18 13:14:47 2020