nixCraft Linux Forum

nixCraft

Linux Tech Support Forum

how to make iptable rules?

This is a discussion on how to make iptable rules? within the Networking, Firewalls and Security forums, part of the Mastering Servers category; Sir , I have one RETHAT AS4 server for internet. Around 300 hundred systems with win XP for different peoples. ...


Go Back   nixCraft Linux Forum > Mastering Servers > Networking, Firewalls and Security

Register FAQ Members List Calendar Mark Forums Read
  #1 (permalink)  
Old 06-12-2008, 03:29 PM
Junior Member
User
 
Join Date: Jun 2008
My distro: Redhat
Posts: 6
Rep Power: 0
saroj is on a distinguished road
Default how to make iptable rules?

Sir ,

I have one RETHAT AS4 server for internet. Around 300 hundred systems with win XP for different peoples. The owner of the systems knows the administrator password of their system. All peoples are in the network.

For accesing internet i gave gateway i.e server ip and DNS of ISP along with system ip and subnet as usual.

Among 300 people I want to give only 15 systems want to connect internet. For others even if they have entered gateway address and dns in the network settings , they could not able access.

Strictly speaking, what ever ips i entered using iptable , that systems only could connect internet others could not.

So may softwares available like squid but i need simple iptable rules.
How to make rules easily?

Experts can easily understand my request and i hope i can get quick response

Thanking u
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 06-13-2008, 10:19 AM
Junior Member
User
 
Join Date: Nov 2007
My distro: Mepis and Debian
Posts: 22
Rep Power: 0
Johnny Utah is on a distinguished road
Default

I'm confused.

You have a Red Hat AS acting as router. All the XP clients are using the Red Hat box as their default gateway. And you want to use iptables on the Red Hat box to forward packets to the real default gateway based on source IP address and block all other packets?

Is that correct or am I wrong?
__________________
Kubuntu user? http://kubuntuway.net
Do you own reptiles? http://redtailconnect.net
Reply With Quote
  #3 (permalink)  
Old 06-13-2008, 04:29 PM
Junior Member
User
 
Join Date: Jun 2008
My distro: Redhat
Posts: 6
Rep Power: 0
saroj is on a distinguished road
Default

Thanks for ur reply

sorry for making confusion

whatever ur assumption exactly correct.

My RETHAT AS4 is a router. For that i need ur answer with easy steps.

Thanks in advance.

I am waiting for ur reply.
Reply With Quote
  #4 (permalink)  
Old 06-14-2008, 01:21 AM
nixcraft's Avatar
Never say die
User
 
Join Date: Jan 2005
Location: BIOS
My distro: Any distro with shell
Posts: 902
Rep Power: 10
nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute
Default

IS RHEL 4 AS configured as router and working from XP?

Code:
LAN - RHEL - Router
Open Router configuration and only allow access from RHEL IP and block everything else

Configure RHEL as router and enable firewall

You can also install squid proxy to tight the security and browsing.
__________________
Vivek | My personal blog
Linux Evangelist
Play hard stay cool
Reply With Quote
  #5 (permalink)  
Old 06-16-2008, 10:17 AM
Junior Member
User
 
Join Date: Jun 2008
My distro: Redhat
Posts: 6
Rep Power: 0
saroj is on a distinguished road
Default

IS RHEL 4 AS configured as router and working from XP?


Code:
LAN - RHEL - Router


I could not understand above statement and code. RHEL server act as a router. Clients are Winxps

Also i installed squid in the same RHEL and it is working fine. Squid I am using for blocking site and i allow internet for particular ip.That is working fine

If people are under squid for them,I gave only ip and subnet in the network settings and in the browser Tools -> Internet option -> connections -> Lan setting -> proxy server -> tick use proxy server and gave the ip address of RHEL and port address 3128. It is working fine

Problem here is , If I remove tick from use proxy server under Lan settings of the browser and in the network setting If i enter default gateway address i.e RHEL ip and DNS , I can able to browse with all sites with no restriction .

These all I explained in my first mail.

I want to allow internet for two groups

For one group of ips I dont want block any sites , they can browse always. This group i am now using iptable. i.e I filled ip ,subnet,gateway and DNS in the netwrk settings. Because this RHEL is made as a router.

For second group , I want block some sites and they are permitted for browsing some particular time . This group I am using squid in the same RHEL i.e i filled only ip, subnet and did modification in the browser settings

Problem here is that most of the second group people knows the first group setting, They simply untick the use proxy server in the browser setting and they just add gatway address and DNS. Now they can browse always without blocking any sites.

What I want is even if the second group people modify network setting .i.e adding gatway and dns and untick the use proxy, They should not able browse they should browse only what time i allow using squid.

How to make iptable rules that only allow the ips first group .
Reply With Quote
Reply

Bookmarks


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)

 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On

Similar Threads

Thread Thread Starter Forum Replies Last Post
How to make a VPN kadiyala.srikanth@gmail.c Linux software 0 05-26-2008 07:16 AM
iptables rules blocking ftp hammooda Linux software 7 09-23-2006 04:24 PM
How do I make backup of ISO CD sweta Solaris/OpenSolaris 1 09-09-2005 05:29 PM
iptables rules for three ethernet brijeshchougule Linux software 2 06-16-2005 02:42 PM
Forum rules vivek Feedback & Site News 0 02-01-2005 11:04 AM


All times are GMT +5.5. The time now is 12:32 AM.


Powered by vBulletin® Version 3.7.2 - Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.2.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36