Showing posts with label firewall. Show all posts
Showing posts with label firewall. Show all posts

Monday, July 24, 2023

iptables/netfilter hooks&rules


                                    | Incoming             ++---------------------++
                                    ↓                      || raw                 ||
                           +-------------------+           || connection tracking ||
                           | NF_IP_PRE_ROUTING |= = = = = =|| mangle              ||
                           +-------------------+           || nat (DNAT)          ||
                                    |                      ++---------------------++
                                    |
                                    ↓                                                ++------------++
                           +------------------+                                      || mangle     ||
                           |                  |         +----------------+           || filter     ||
                           | routing decision |-------->| NF_IP_LOCAL_IN |= = = = = =|| security   ||
                           |                  |         +----------------+           || nat (SNAT) ||
                           +------------------+                 |                    ++------------++
                                    |                           |
                                    |                           ↓
                                    |                  +-----------------+
                                    |                  | local processes |
                                    |                  +-----------------+
                                    |                           |
                                    |                           |                    ++---------------------++
 ++------------++                   ↓                           ↓                    || raw                 ||
 || mangle     ||           +---------------+          +-----------------+           || connection tracking ||
 || filter     ||= = = = = =| NF_IP_FORWARD |          | NF_IP_LOCAL_OUT |= = = = = =|| mangle              ||
 || security   ||           +---------------+          +-----------------+           || nat (DNAT)          ||
 ++------------++                   |                           |                    || filter              ||
                                    |                           |                    || security            ||
                                    ↓                           |                    ++---------------------++
                           +------------------+                 |
                           |                  |                 |
                           | routing decision |<----------------+
                           |                  |
                           +------------------+
                                    |
                                    |
                                    ↓
                           +--------------------+           ++------------++
                           | NF_IP_POST_ROUTING |= = = = = =|| mangle     ||
                           +--------------------+           || nat (SNAT) ||
                                    |                       ++------------++
                                    | Outgoing
                                    ↓

Deep dive into iptables on k3s node

Was struggling as I could not get "ss" or "netstat" to show me which port is listening on internet:

A Screenshot explains everything ( regarding 32233 port): 



Wednesday, July 19, 2023

ufw cheatsheet

Why does Linux have such a wide array of different firewalls? Have to make cheatsheet for every single one of them...here it is the ufw one:

Conf files:
/etc/ufw/user.rules
/etc/ufw/user6.rules

ufw enable
ufw disable
ufw show added
ufw status verbose
ufw status numbered
ufw allow 22/tcp
ufw deny 22/up
ufw delete deny 22/udp
ufw delete 2
ufw allow from 192.168.2.0/24 to 192.168.2.25 port 22 proto tcp
ufw allow from 192.168.2.0/24 to 192.168.2.26 port 22 proto tcp
ufw allow from 192.168.1.155 to any port 22 proto tcp
ufw allow 80/tcp comment 'accept Web'
ufw allow 443/tcp comment 'accept HTTPS'

Thursday, November 3, 2022

Flush iptables for troubleshooting

iptables -P INPUT ACCEPT

iptables -P OUTPUT ACCEPT

iptables -P FORWARD ACCEPT

iptables -F



Tuesday, March 22, 2022

FirewallD

 Have been working on iptables for yrs and still cant get used to the more "friendly" firewalld, well, here it is the cheatsheet:

  • -drop: The lowest level of trust. All incoming connections are dropped without reply and only outgoing connections are possible.
  • -block: Similar to the above, but instead of simply dropping connections, incoming requests are rejected with an icmp-host-prohibited or icmp6-adm-prohibited message.
  • -public: Represents public, untrusted networks. You don’t trust other computers but may allow selected incoming connections on a case-by-case basis.
  • -external: External networks in the event that you are using the firewall as your gateway. It is configured for NAT masquerading so that your internal network remains private but reachable.
  • -internal: The other side of the external zone, used for the internal portion of a gateway. The computers are fairly trustworthy and some additional services are available.
  • -dmz: Used for computers located in a DMZ (isolated computers that will not have access to the rest of your network). Only certain incoming connections are allowed.
  • -work: Used for work machines. Trust most of the computers in the network. A few more services might be allowed.
  • -home: A home environment. It generally implies that you trust most of the other computers and that a few more services will be accepted.
  • -trusted: Trust all of the machines in the network. The most open of the available options and should be used sparingly.

firewall-cmd --state
firewall-cmd --get-default-zone
firewall-cmd --get-active-zones
firewall-cmd --list-all
firewall-cmd --get-zones

firewall-cmd --zone=home --list-all
firewall-cmd --zone=home --list-all-zones
firewall-cmd --zone=home --change-interface=eth0

firewall-cmd --set-default-zone=home
firewall-cmd --get-services

Service Definition:
/usr/lib/firewalld/services
firewall-cmd --reload
firewall-cmd --get-services

firewall-cmd --zone=public --add-service=http
firewall-cmd --zone=public --permanent --add-service=http

firewall-cmd --zone=public --list-services

firewall-cmd --zone=public --add-port=5000/tcp
firewall-cmd --zone=public --permanent --add-port=4990-4999/udp
firewall-cmd --permanent --zone=public --remove-service=dhcpv6-client
firewall-cmd --zone=public --permanent --remove-port=443/tcp
firewall-cmd --zone=public --list-ports
firewall-cmd --runtime-to-permanent

Targets definition:
  • ACCEPT: accept the packet.
  • %%REJECT%%: reject the packet, returning a reject reply.
  • DROP: drop the packet, returning no reply.
  • default: don't do anything. The zone washes its hands of the problem, and kicks it "upstairs".
firewall-cmd --permanent --zone=public --set-target=DROP

Friday, June 25, 2021

Linux firewall related settings

============iptables============
#!/bin/bash
iptables -F
iptables -P INPUT DROP
iptables -P OUTPUT ACCEPT
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -i lan0 -j ACCEPT
iptables -A INPUT -i ens21f0 -j ACCEPT
iptables -A INPUT -i ens21f1 -j ACCEPT
iptables -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT

=============NAT via firewall-cmd=================

vim /etc/sysctl.conf 
net.ipv4.ip_forward = 1
sysctl -p

#define zone
firewall-cmd --permanent --zone=external --change-interface=eth0 
firewall-cmd --permanent --zone=internal --change-interface=eth1

#set NAT masquerade
firewall-cmd --zone=external --add-masquerade --permanent

#NAT rules
firewall-cmd --permanent --direct --passthrough ipv4 -t nat -I POSTROUTING -o em1 -j MASQUERADE -s 172.16.10.0/24
firewall-cmd --reload

#Check:
[root@620 ~]# firewall-cmd  --direct --get-passthroughs ipv4 -t nat -I POSTROUTING -o em1 -j MASQUERADE -s 172.16.10.0/24