nixCraft Linux Forum

nixCraft

Linux / UNIX Tech Support Forum

how to make iptable rules?

This is a discussion on how to make iptable rules? within the Networking, Firewalls and Security forums, part of the Mastering Servers category; Sir , I have one RETHAT AS4 server for internet. Around 300 hundred systems with win XP for different peoples. ...


Go Back   nixCraft Linux Forum > Mastering Servers > Networking, Firewalls and Security

Linux answers from nixCraft.


Networking, Firewalls and Security No it's not a secret. Talk about firewalls and security issues.

Reply

 

LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 12-06-2008, 03:29 PM
Junior Member
User
 
Join Date: Jun 2008
OS: Redhat
Posts: 7
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
saroj is on a distinguished road
Default how to make iptable rules?

Sir ,

I have one RETHAT AS4 server for internet. Around 300 hundred systems with win XP for different peoples. The owner of the systems knows the administrator password of their system. All peoples are in the network.

For accesing internet i gave gateway i.e server ip and DNS of ISP along with system ip and subnet as usual.

Among 300 people I want to give only 15 systems want to connect internet. For others even if they have entered gateway address and dns in the network settings , they could not able access.

Strictly speaking, what ever ips i entered using iptable , that systems only could connect internet others could not.

So may softwares available like squid but i need simple iptable rules.
How to make rules easily?

Experts can easily understand my request and i hope i can get quick response

Thanking u
Reply With Quote
  #2 (permalink)  
Old 13-06-2008, 10:19 AM
Junior Member
User
 
Join Date: Nov 2007
OS: Mepis and Debian
Posts: 22
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
Johnny Utah is on a distinguished road
Default

I'm confused.

You have a Red Hat AS acting as router. All the XP clients are using the Red Hat box as their default gateway. And you want to use iptables on the Red Hat box to forward packets to the real default gateway based on source IP address and block all other packets?

Is that correct or am I wrong?
__________________
Kubuntu user? http://kubuntuway.net
Do you own reptiles? http://redtailconnect.net
Reply With Quote
  #3 (permalink)  
Old 13-06-2008, 04:29 PM
Junior Member
User
 
Join Date: Jun 2008
OS: Redhat
Posts: 7
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
saroj is on a distinguished road
Default

Thanks for ur reply

sorry for making confusion

whatever ur assumption exactly correct.

My RETHAT AS4 is a router. For that i need ur answer with easy steps.

Thanks in advance.

I am waiting for ur reply.
Reply With Quote
  #4 (permalink)  
Old 14-06-2008, 01:21 AM
nixcraft's Avatar
Never say die
User
 
Join Date: Jan 2005
Location: BIOS
OS: RHEL
Scripting language: Bash and Python
Posts: 2,710
Thanks: 11
Thanked 245 Times in 184 Posts
Rep Power: 10
nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute nixcraft has a reputation beyond repute
Default

IS RHEL 4 AS configured as router and working from XP?

Code:
LAN - RHEL - Router
Open Router configuration and only allow access from RHEL IP and block everything else

Configure RHEL as router and enable firewall

You can also install squid proxy to tight the security and browsing.
__________________
Vivek Gite
Linux Evangelist
Be proud RHEL user, and let the world know about your enterprise choices! Join RedHat user group.
Always use CODE tags for posting system output and commands!
Do you run a Linux? Let's face it, you need help
Reply With Quote
  #5 (permalink)  
Old 16-06-2008, 10:17 AM
Junior Member
User
 
Join Date: Jun 2008
OS: Redhat
Posts: 7
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
saroj is on a distinguished road
Default

IS RHEL 4 AS configured as router and working from XP?


Code:
LAN - RHEL - Router


I could not understand above statement and code. RHEL server act as a router. Clients are Winxps

Also i installed squid in the same RHEL and it is working fine. Squid I am using for blocking site and i allow internet for particular ip.That is working fine

If people are under squid for them,I gave only ip and subnet in the network settings and in the browser Tools -> Internet option -> connections -> Lan setting -> proxy server -> tick use proxy server and gave the ip address of RHEL and port address 3128. It is working fine

Problem here is , If I remove tick from use proxy server under Lan settings of the browser and in the network setting If i enter default gateway address i.e RHEL ip and DNS , I can able to browse with all sites with no restriction .

These all I explained in my first mail.

I want to allow internet for two groups

For one group of ips I dont want block any sites , they can browse always. This group i am now using iptable. i.e I filled ip ,subnet,gateway and DNS in the netwrk settings. Because this RHEL is made as a router.

For second group , I want block some sites and they are permitted for browsing some particular time . This group I am using squid in the same RHEL i.e i filled only ip, subnet and did modification in the browser settings

Problem here is that most of the second group people knows the first group setting, They simply untick the use proxy server in the browser setting and they just add gatway address and DNS. Now they can browse always without blocking any sites.

What I want is even if the second group people modify network setting .i.e adding gatway and dns and untick the use proxy, They should not able browse they should browse only what time i allow using squid.

How to make iptable rules that only allow the ips first group .
Reply With Quote
  #6 (permalink)  
Old 14-11-2008, 10:33 AM
Junior Member
User
 
Join Date: Nov 2008
OS: REHL
Posts: 1
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
Kishor is on a distinguished road
Default I want to do exact same thing

Hi there,

have you found solution to your problem ?

I do want to do exact same thing in our office.

Thanks for reply,
Kishor
Reply With Quote
  #7 (permalink)  
Old 14-11-2008, 03:23 PM
Junior Member
User
 
Join Date: Jun 2008
OS: Redhat
Posts: 7
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
saroj is on a distinguished road
Default

Sorry,

Still i did not find the solution

Thank u
Reply With Quote
  #8 (permalink)  
Old 11-03-2009, 06:18 PM
nix's Avatar
nix nix is offline
Junior Member
User
 
Join Date: Feb 2007
Location: Pune, India
OS: Redhat, Sun Solaris
Posts: 12
Thanks: 0
Thanked 0 Times in 0 Posts
Rep Power: 0
nix
Default

Hi,

Squid Configuration :


* Use Squid as a transparent proxy, with this settings users can browse the internet only through Squid Proxy.

* Configure Squid filtration rules as per the IP Address's which you want to allow or restrict.

IPtables Configuration :

* Block restricted IP's on IPtables for request Proxy port ( Default port 3128 )
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)

 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads

Thread Thread Starter Forum Replies Last Post
How to make a VPN kadiyala.srikanth@gmail.c Linux software 0 26-05-2008 07:16 AM
iptables rules blocking ftp hammooda Linux software 7 23-09-2006 04:24 PM
How do I make backup of ISO CD sweta Solaris/OpenSolaris 1 09-09-2005 05:29 PM
iptables rules for three ethernet brijeshchougule Linux software 2 16-06-2005 02:42 PM
Forum rules vivek Feedback & Site News 0 01-02-2005 11:04 AM


All times are GMT +5.5. The time now is 06:36 AM.


Powered by vBulletin® Version 3.8.5 - Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2
©2005-2010 nixCraft. All rights reserved

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38