SHARE
TWEET
Untitled
a guest
Feb 8th, 2016
18
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
- We configured ipv4 firewall rules for one of our server in such a way it should allow only configured ip's on port 2070.
- ----------
- ##ipv4
- iptables -L
- o/p:
- target prot opt source destination
- fail2ban-ssh tcp -- anywhere anywhere multiport dports ssh
- ACCEPT tcp -- 1.2.3.4 anywhere tcp dpt:2070
- ACCEPT tcp -- 5.6.7.8 anywhere tcp dpt:2070
- ACCEPT tcp -- 9.10.11.12.13 anywhere tcp dpt:2070
- ACCEPT tcp -- 10.11.13.12 anywhere tcp dpt:2070
- DROP tcp -- anywhere anywhere tcp dpt:2070
- Chain FORWARD (policy ACCEPT)
- target prot opt source destination
- Chain OUTPUT (policy ACCEPT)
- target prot opt source destination
- Few days later we came across a situation that we should configure ip firewall rules in such a way "it should allow know ipv4& ipv6 address".
- DROP tcp -- anywhere anywhere tcp dpt:2070
- Above IPv4 DROP Rule rejecting the all unknow ipv4 address, but it is also rejecting the ipv6 connections too.
- I need to modify the configurations in such a way,
- 1. it should allow only configured ipv4& ipv6 address on port 2070.
- Please give suggestions
- ----------
- ##ipv4
- iptables -L
- o/p:
- target prot opt source destination
- fail2ban-ssh tcp -- anywhere anywhere multiport dports ssh
- ACCEPT tcp -- 1.2.3.4 anywhere tcp dpt:2070
- ACCEPT tcp -- 5.6.7.8 anywhere tcp dpt:2070
- ACCEPT tcp -- 9.10.11.12.13 anywhere tcp dpt:2070
- ACCEPT tcp -- 10.11.13.12 anywhere tcp dpt:2070
- DROP tcp -- anywhere anywhere tcp dpt:2070
- Chain FORWARD (policy ACCEPT)
- target prot opt source destination
- Chain OUTPUT (policy ACCEPT)
- target prot opt source destination
- --------
- ##ipv6
- ip6tables -L
- o/p:
- target prot opt source destination
- ACCEPT tcp 2606:a000:122d:113:f456:ca4d:fe2:2656 anywhere tcp dpt:2070
- DROP tcp anywhere anywhere tcp dpt:2070
- Chain FORWARD (policy ACCEPT)
- target prot opt source destination
- Chain OUTPUT (policy ACCEPT)
- target prot opt source destination
RAW Paste Data
