| Incoming ++---------------------++
↓ || raw ||
+-------------------+ || connection tracking ||
| NF_IP_PRE_ROUTING |= = = = = =|| mangle ||
+-------------------+ || nat (DNAT) ||
| ++---------------------++
|
↓ ++------------++
+------------------+ || mangle ||
| | +----------------+ || filter ||
| routing decision |-------->| NF_IP_LOCAL_IN |= = = = = =|| security ||
| | +----------------+ || nat (SNAT) ||
+------------------+ | ++------------++
| |
| ↓
| +-----------------+
| | local processes |
| +-----------------+
| |
| | ++---------------------++
++------------++ ↓ ↓ || raw ||
|| mangle || +---------------+ +-----------------+ || connection tracking ||
|| filter ||= = = = = =| NF_IP_FORWARD | | NF_IP_LOCAL_OUT |= = = = = =|| mangle ||
|| security || +---------------+ +-----------------+ || nat (DNAT) ||
++------------++ | | || filter ||
| | || security ||
↓ | ++---------------------++
+------------------+ |
| | |
| routing decision |<----------------+
| |
+------------------+
|
|
↓
+--------------------+ ++------------++
| NF_IP_POST_ROUTING |= = = = = =|| mangle ||
+--------------------+ || nat (SNAT) ||
| ++------------++
| Outgoing
↓
Monday, July 24, 2023
iptables/netfilter hooks&rules
Deep dive into iptables on k3s node
Was struggling as I could not get "ss" or "netstat" to show me which port is listening on internet:
A Screenshot explains everything ( regarding 32233 port):
Wednesday, July 19, 2023
ufw cheatsheet
/etc/ufw/user.rules
/etc/ufw/user6.rules
ufw enable
ufw disable
ufw show added
ufw status verbose
ufw status numbered
ufw allow 22/tcp
ufw deny 22/up
ufw delete deny 22/udp
ufw delete 2
ufw allow from 192.168.2.0/24 to 192.168.2.25 port 22 proto tcp
ufw allow from 192.168.2.0/24 to 192.168.2.26 port 22 proto tcp
ufw allow from 192.168.1.155 to any port 22 proto tcp
ufw allow 80/tcp comment 'accept Web'
ufw allow 443/tcp comment 'accept HTTPS'
Wednesday, May 18, 2022
iptables NAT
vim /etc/sysctl.conf
net.ipv4.ip_forward = 1
sysctl -p
# iptables -t nat -P POSTROUTING DROP
# iptables -t nat -A POSTROUTING -o interfacename -j MASQUERADE
Tuesday, March 22, 2022
FirewallD
- -drop: The lowest level of trust. All incoming connections are dropped without reply and only outgoing connections are possible.
- -block: Similar to the above, but instead of simply dropping connections, incoming requests are rejected with an icmp-host-prohibited or icmp6-adm-prohibited message.
- -public: Represents public, untrusted networks. You don’t trust other computers but may allow selected incoming connections on a case-by-case basis.
- -external: External networks in the event that you are using the firewall as your gateway. It is configured for NAT masquerading so that your internal network remains private but reachable.
- -internal: The other side of the external zone, used for the internal portion of a gateway. The computers are fairly trustworthy and some additional services are available.
- -dmz: Used for computers located in a DMZ (isolated computers that will not have access to the rest of your network). Only certain incoming connections are allowed.
- -work: Used for work machines. Trust most of the computers in the network. A few more services might be allowed.
- -home: A home environment. It generally implies that you trust most of the other computers and that a few more services will be accepted.
- -trusted: Trust all of the machines in the network. The most open of the available options and should be used sparingly.
- ACCEPT: accept the packet.
- %%REJECT%%: reject the packet, returning a reject reply.
- DROP: drop the packet, returning no reply.
- default: don't do anything. The zone washes its hands of the problem, and kicks it "upstairs".
Friday, August 27, 2021
Cumulus....cumulus.....
net add interface swp11 link autoneg on
net add interface swp11 link speed 40000
ip link set dev swp3s0 up
net commit
sudo l1-show swp3s0
sudo cat /etc/lsb-release
sudo ethtool -m swp1
sudo net del interface swp3s0
sudo net add interface swp3 breakout 4x
====sometimes the breakout command doesnt work, then try to nano the ports.conf====
sudo nano /etc/cumulus/ports.conf
/etc/network/interfaces
Thursday, August 12, 2021
EVE with Wireshark remote capture
[HKEY_CLASSES_ROOT\capture]
@="URL:UNetLab interface capture"
"URL Protocol"=""
[HKEY_CLASSES_ROOT\capture\shell]
[HKEY_CLASSES_ROOT\capture\shell\open]
[HKEY_CLASSES_ROOT\capture\shell\open\command]
@="\"C:\\Program Files\\Wireshark\\wireshark_wrapper.bat\" %1"
Friday, July 23, 2021
Netplan config
sysadm@linuxtechi:~$ sudo vi /etc/netplan/00-installer-config.yaml
# This is the network config written by 'subiquity'
network:
ethernets:
enp0s3:
dhcp4: true
version: 2
Above are the default entries, which shows that interface “enp0s3” is getting the IP from DHCP server. As it is an yaml file, so while making the changes in the file we must follow correct indentation. Add the following lines to the yaml file,
network:
ethernets:
enp0s3:
addresses: [192.168.1.3/24]
gateway4: 192.168.1.1
nameservers:
addresses: [4.2.2.2, 8.8.8.8]
version: 2
Friday, June 25, 2021
Linux firewall related settings
Linux network configuration
SSH tunnel: