PDA

Archiv verlassen und diese Seite im Standarddesign anzeigen : iptables blockt scheinbar zuviel



Nighthawk
27.03.02, 10:05
Der Teil mit den Regeln aus meinem Firewallscript:


# Flush all Rules
iptables -F

# Accept ourselves
iptables -A INPUT -s 127.0.0.1/32 -d 127.0.0.1/32 -j ACCEPT

# Accept ICMP
iptables -A INPUT -p icmp -j ACCEPT

# DNS
iptables -A INPUT -p udp --source-port 53 -m state --state ESTABLISHED -j ACCEPT
# FTP
iptables -A INPUT -p tcp --destination-port 21 -m state --state NEW,ESTABLISHED -j ACCEPT
iptables -A INPUT -p tcp --destination-port 20 -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -p tcp ! --syn --source-port 20 --destination-port 1024:65535 -m state --state ESTABLISHED,RELATED -j ACCEPT
# HTTP
iptables -A INPUT -p tcp --destination-port 80 -m state --state NEW,ESTABLISHED -j ACCEPT
iptables -A INPUT -p tcp --destination-port 443 -m state --state NEW,ESTABLISHED -j ACCEPT
iptables -A INPUT -p tcp --source-port 443 -m state --state ESTABLISHED,RELATED -j ACCEPT
# SMTP
iptables -A INPUT -p tcp --destination-port 25 -m state --state NEW,ESTABLISHED -j ACCEPT
# SSH
iptables -A INPUT -p tcp --destination-port 22 -m state --state NEW,ESTABLISHED -j ACCEPT

# Policies
iptables -P INPUT DROP
iptables -P OUTPUT ACCEPT
iptables -P FORWARD DROP

Sollte das so funktionieren? Besonders der HTTP Teil?

Nighthawk
28.03.02, 08:58
Hilfe...