| Incoming ++---------------------++
↓ || raw ||
+-------------------+ || connection tracking ||
| NF_IP_PRE_ROUTING |= = = = = =|| mangle ||
+-------------------+ || nat (DNAT) ||
| ++---------------------++
|
↓ ++------------++
+------------------+ || mangle ||
| | +----------------+ || filter ||
| routing decision |-------->| NF_IP_LOCAL_IN |= = = = = =|| security ||
| | +----------------+ || nat (SNAT) ||
+------------------+ | ++------------++
| |
| ↓
| +-----------------+
| | local processes |
| +-----------------+
| |
| | ++---------------------++
++------------++ ↓ ↓ || raw ||
|| mangle || +---------------+ +-----------------+ || connection tracking ||
|| filter ||= = = = = =| NF_IP_FORWARD | | NF_IP_LOCAL_OUT |= = = = = =|| mangle ||
|| security || +---------------+ +-----------------+ || nat (DNAT) ||
++------------++ | | || filter ||
| | || security ||
↓ | ++---------------------++
+------------------+ |
| | |
| routing decision |<----------------+
| |
+------------------+
|
|
↓
+--------------------+ ++------------++
| NF_IP_POST_ROUTING |= = = = = =|| mangle ||
+--------------------+ || nat (SNAT) ||
| ++------------++
| Outgoing
↓
Showing posts with label firewall. Show all posts
Showing posts with label firewall. Show all posts
Monday, July 24, 2023
iptables/netfilter hooks&rules
Deep dive into iptables on k3s node
Was struggling as I could not get "ss" or "netstat" to show me which port is listening on internet:
A Screenshot explains everything ( regarding 32233 port):
Wednesday, July 19, 2023
ufw cheatsheet
Why does Linux have such a wide array of different firewalls? Have to make cheatsheet for every single one of them...here it is the ufw one:
Conf files:
/etc/ufw/user.rules
/etc/ufw/user6.rules
/etc/ufw/user.rules
/etc/ufw/user6.rules
ufw enable
ufw disable
ufw show added
ufw status verbose
ufw status numbered
ufw allow 22/tcp
ufw deny 22/up
ufw delete deny 22/udp
ufw delete 2
ufw allow from 192.168.2.0/24 to 192.168.2.25 port 22 proto tcp
ufw allow from 192.168.2.0/24 to 192.168.2.26 port 22 proto tcp
ufw allow from 192.168.1.155 to any port 22 proto tcp
ufw allow 80/tcp comment 'accept Web'
ufw allow 443/tcp comment 'accept HTTPS'
Thursday, November 3, 2022
Flush iptables for troubleshooting
iptables -P INPUT ACCEPT
iptables -P OUTPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -F
Tuesday, March 22, 2022
FirewallD
Have been working on iptables for yrs and still cant get used to the more "friendly" firewalld, well, here it is the cheatsheet:
- -drop: The lowest level of trust. All incoming connections are dropped without reply and only outgoing connections are possible.
- -block: Similar to the above, but instead of simply dropping connections, incoming requests are rejected with an icmp-host-prohibited or icmp6-adm-prohibited message.
- -public: Represents public, untrusted networks. You don’t trust other computers but may allow selected incoming connections on a case-by-case basis.
- -external: External networks in the event that you are using the firewall as your gateway. It is configured for NAT masquerading so that your internal network remains private but reachable.
- -internal: The other side of the external zone, used for the internal portion of a gateway. The computers are fairly trustworthy and some additional services are available.
- -dmz: Used for computers located in a DMZ (isolated computers that will not have access to the rest of your network). Only certain incoming connections are allowed.
- -work: Used for work machines. Trust most of the computers in the network. A few more services might be allowed.
- -home: A home environment. It generally implies that you trust most of the other computers and that a few more services will be accepted.
- -trusted: Trust all of the machines in the network. The most open of the available options and should be used sparingly.
firewall-cmd --state
firewall-cmd --get-default-zone
firewall-cmd --get-active-zones
firewall-cmd --list-all
firewall-cmd --get-zones
firewall-cmd --zone=home --list-all
firewall-cmd --zone=home --list-all-zones
firewall-cmd --zone=home --change-interface=eth0
firewall-cmd --set-default-zone=home
firewall-cmd --get-services
Service Definition:
/usr/lib/firewalld/services
firewall-cmd --reload
firewall-cmd --get-services
firewall-cmd --zone=public --add-service=http
firewall-cmd --zone=public --permanent --add-service=http
firewall-cmd --zone=public --list-services
firewall-cmd --zone=public --add-port=5000/tcp
firewall-cmd --zone=public --permanent --add-port=4990-4999/udp
firewall-cmd --permanent --zone=public --remove-service=dhcpv6-client
firewall-cmd --zone=public --permanent --remove-port=443/tcp
firewall-cmd --zone=public --list-ports
firewall-cmd --runtime-to-permanent
Targets definition:
- ACCEPT: accept the packet.
- %%REJECT%%: reject the packet, returning a reject reply.
- DROP: drop the packet, returning no reply.
- default: don't do anything. The zone washes its hands of the problem, and kicks it "upstairs".
firewall-cmd --permanent --zone=public --set-target=DROP
Friday, June 25, 2021
Linux firewall related settings
============iptables============
#!/bin/bash
iptables -F
iptables -P INPUT DROP
iptables -P OUTPUT ACCEPT
iptables -A INPUT -i lo -j ACCEPT
iptables -A INPUT -i lan0 -j ACCEPT
iptables -A INPUT -i ens21f0 -j ACCEPT
iptables -A INPUT -i ens21f1 -j ACCEPT
iptables -A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
=============NAT via firewall-cmd=================
vim /etc/sysctl.conf
net.ipv4.ip_forward = 1
sysctl -p
#define zone
firewall-cmd --permanent --zone=external --change-interface=eth0
firewall-cmd --permanent --zone=internal --change-interface=eth1
#set NAT masquerade
firewall-cmd --zone=external --add-masquerade --permanent
#NAT rules
firewall-cmd --permanent --direct --passthrough ipv4 -t nat -I POSTROUTING -o em1 -j MASQUERADE -s 172.16.10.0/24
firewall-cmd --reload
#Check:
[root@620 ~]# firewall-cmd --direct --get-passthroughs ipv4 -t nat -I POSTROUTING -o em1 -j MASQUERADE -s 172.16.10.0/24
Subscribe to:
Posts (Atom)