Настройка iptables
Drakon 5 июля, 2013 - 19:17
Сделал в iptables запрет всех входящих пакетов, кроме TCP на 80 порт и ещё некоторых, но в логи всё равно сыпятся ошибки про непропущенные TCP-пакеты на 80 порт. В чём может быть дело?
Правила iptables
iptables -P INPUT DROP iptables -P FORWARD DROP iptables -P OUTPUT DROP iptables -A INPUT -d 9.9.9.9 -i eth3 -p tcp --dport 80 -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT iptables -A OUTPUT -s 9.9.9.9 -o eth3 -p tcp --sport 80 -m conntrack --ctstate ESTABLISHED -j ACCEPT
tail /var/log/kern.log
Jul 5 19:15:11 isds2 kernel: [1790653.414700] IPTables Packet Dropped: IN=eth3 OUT= MAC=00:1e:67:06:a1:0c:00:25:84:01:9e:40:08:00 SRC=188.242.175.210 DST=9.9.9.9 LEN=40 TOS=0x00 PREC=0x00 TTL=120 ID=24568 DF PROTO=TCP SPT=1360 DPT=80 WINDOW=65535 RES=0x00 ACK FIN URGP=0 Jul 5 19:15:14 isds2 kernel: [1790656.760844] IPTables Packet Dropped: IN=eth3 OUT= MAC=00:1e:67:06:a1:0c:00:25:84:01:9e:40:08:00 SRC=213.87.123.169 DST=9.9.9.9 LEN=40 TOS=0x00 PREC=0x00 TTL=107 ID=1557 PROTO=TCP SPT=56968 DPT=80 WINDOW=0 RES=0x00 ACK RST URGP=0 Jul 5 19:15:19 isds2 kernel: [1790662.273652] IPTables Packet Dropped: IN=eth3 OUT= MAC=00:1e:67:06:a1:0c:00:25:84:01:9e:40:08:00 SRC=193.200.10.71 DST=9.9.9.9 LEN=52 TOS=0x00 PREC=0x00 TTL=55 ID=7067 PROTO=TCP SPT=54950 DPT=80 WINDOW=65535 RES=0x00 ACK FIN URGP=0 Jul 5 19:15:26 isds2 kernel: [1790668.865001] IPTables Packet Dropped: IN=eth3 OUT= MAC=00:1e:67:06:a1:0c:00:25:84:01:9e:40:08:00 SRC=212.248.39.130 DST=9.9.9.9 LEN=40 TOS=0x00 PREC=0x00 TTL=117 ID=7506 PROTO=TCP SPT=12503 DPT=80 WINDOW=65535 RES=0x00 ACK FIN URGP=0 Jul 5 19:15:26 isds2 kernel: [1790668.873620] IPTables Packet Dropped: IN=eth3 OUT= MAC=00:1e:67:06:a1:0c:00:25:84:01:9e:40:08:00 SRC=212.248.39.130 DST=9.9.9.9 LEN=40 TOS=0x00 PREC=0x00 TTL=117 ID=7607 PROTO=TCP SPT=12506 DPT=80 WINDOW=65535 RES=0x00 ACK FIN URGP=0 Jul 5 19:15:26 isds2 kernel: [1790668.873680] IPTables Packet Dropped: IN=eth3 OUT= MAC=00:1e:67:06:a1:0c:00:25:84:01:9e:40:08:00 SRC=212.248.39.130 DST=9.9.9.9 LEN=40 TOS=0x00 PREC=0x00 TTL=117 ID=7608 PROTO=TCP SPT=12505 DPT=80 WINDOW=65535 RES=0x00 ACK FIN URGP=0 Jul 5 19:15:26 isds2 kernel: [1790668.874131] IPTables Packet Dropped: IN=eth3 OUT= MAC=00:1e:67:06:a1:0c:00:25:84:01:9e:40:08:00 SRC=212.248.39.130 DST=9.9.9.9 LEN=40 TOS=0x00 PREC=0x00 TTL=117 ID=7612 PROTO=TCP SPT=12504 DPT=80 WINDOW=65535 RES=0x00 ACK FIN URGP=0 Jul 5 19:15:26 isds2 kernel: [1790668.874294] IPTables Packet Dropped: IN=eth3 OUT= MAC=00:1e:67:06:a1:0c:00:25:84:01:9e:40:08:00 SRC=212.248.39.130 DST=9.9.9.9 LEN=40 TOS=0x00 PREC=0x00 TTL=117 ID=7613 PROTO=TCP SPT=12497 DPT=80 WINDOW=65535 RES=0x00 ACK FIN URGP=0 Jul 5 19:15:26 isds2 kernel: [1790668.874405] IPTables Packet Dropped: IN=eth3 OUT= MAC=00:1e:67:06:a1:0c:00:25:84:01:9e:40:08:00 SRC=212.248.39.130 DST=9.9.9.9 LEN=40 TOS=0x00 PREC=0x00 TTL=117 ID=7614 PROTO=TCP SPT=12502 DPT=80 WINDOW=65535 RES=0x00 ACK FIN URGP=0 Jul 5 19:15:26 isds2 kernel: [1790669.085639] IPTables Packet Dropped: IN=eth3 OUT= MAC=00:1e:67:06:a1:0c:00:25:84:01:9e:40:08:00 SRC=212.248.39.130 DST=9.9.9.9 LEN=40 TOS=0x00 PREC=0x00 TTL=117 ID=7711 PROTO=TCP SPT=12503 DPT=80 WINDOW=65535 RES=0x00 ACK FIN URGP=0 Jul 5 19:15:26 isds2 kernel: [1790669.194829] IPTables Packet Dropped: IN=eth3 OUT= MAC=00:1e:67:06:a1:0c:00:25:84:01:9e:40:08:00 SRC=212.248.39.130 DST=9.9.9.9 LEN=40 TOS=0x00 PREC=0x00 TTL=117 ID=7713 PROTO=TCP SPT=12506 DPT=80 WINDOW=65535 RES=0x00 ACK FIN URGP=0 Jul 5 19:15:26 isds2 kernel: [1790669.194851] IPTables Packet Dropped: IN=eth3 OUT= MAC=00:1e:67:06:a1:0c:00:25:84:01:9e:40:08:00 SRC=212.248.39.130 DST=9.9.9.9 LEN=40 TOS=0x00 PREC=0x00 TTL=117 ID=7714 PROTO=TCP SPT=12505 DPT=80 WINDOW=65535 RES=0x00 ACK FIN URGP=0 Jul 5 19:15:27 isds2 kernel: [1790669.631764] IPTables Packet Dropped: IN=eth3 OUT= MAC=00:1e:67:06:a1:0c:00:25:84:01:9e:40:08:00 SRC=212.248.39.130 DST=9.9.9.9 LEN=40 TOS=0x00 PREC=0x00 TTL=117 ID=7769 PROTO=TCP SPT=12503 DPT=80 WINDOW=65535 RES=0x00 ACK FIN URGP=0
»
- Для комментирования войдите или зарегистрируйтесь
А где правило на OUT?
А где правило на OUT?
Не грусти, товарищ! Всё хорошо, beautiful good!