Securing and Optimizing Linux:RedHat Edition | All about OS

The firewall scripts files

Категория: Securing and Optimizing

$EXTERNAL_INTERFACE -s 65.0.0.0/8 -j DENY -ipchains -A input -i $EXTERNAL_INTERFACE -s 66.0.0.0/8 -j DENY -ipchains -A input -i $EXTERNAL_INTERFACE -s 67.0.0.0/8 -j DENY -ipchains -A input -i $EXTERNAL_INTERFACE -s 68.0.0.0/8 -j DENY -ipchains -A input -i $EXTERNAL_INTERFACE -s 69.0.0.0/8 -j DENY -ipchains -A input -i $EXTERNAL_INTERFACE -s 70.0.0.0/8 -j DENY -ipchains -A input -i $EXTERNAL_INTERFACE -s 71.0.0.0/8 -j DENY -ipchains -A input -i $EXTERNAL_INTERFACE -s 72.0.0.0/8 -j DENY -ipchains -A input -i $EXTERNAL_INTERFACE -s 73.0.0.0/8 -j DENY -ipchains -A input -i $EXTERNAL_INTERFACE -s 74.0.0.0/8 -j DENY -
ipchains -A input -i $EXTERNAL_INTERFACE -s 75.0.0.0/8 -j DENY -I ipchains -A input -i $EXTERNAL_INTERFACE -s 76.0.0.0/8 -j DENY -I ipchains -A input -i $EXTERNAL_INTERFACE -s 77.0.0.0/8 -j DENY -I ipchains -A input -i $EXTERNAL_INTERFACE -s 78.0.0.0/8 -j DENY -I ipchains -A input -i $EXTERNAL_INTERFACE -s 79.0.0.0/8 -j DENY -I
#80: 01010000 -14 masks 80-95
ipchains -A input -i $EXTERNAL_INTERFACE -s 80.0.0.0/4 -j DENY -I
# 96: 01100000 -14 makses 96-111
ipchains -A input -i $EXTERNAL_INTERFACE -s 96.0.0.0/4 -j DENY -I

#126:01111110
-A input -A input -A input -A input -A input -A input -A input -A input -A input -A input -A input -A input -A input -A input -A input
ipchains ipchains ipchains ipchains ipchains ipchains ipchains ipchains ipchains ipchains ipchains ipchains ipchains ipchains ipchains

- /3 includes 127 - need 112–i $EXTERNAL_INTERFACE -i $EXTERNAL_INTERFACE -i $EXTERNAL_INTERFACE -i $EXTERNAL_INTERFACE -i $EXTERNAL_INTERFACE -i $EXTERNAL_INTERFACE -i $EXTERNAL_INTERFACE -i $EXTERNAL_INTERFACE -i $EXTERNAL_INTERFACE -i $EXTERNAL_INTERFACE -i $EXTERNAL_INTERFACE -i $EXTERNAL_INTERFACE -i $EXTERNAL_INTERFACE -i $EXTERNAL_INTERFACE -i$EXTERNAL INTERFACE

126 spelled out -s112.0.0.0/8 -j -s113.0.0.0/8-j -s114.0.0.0/8 -j -s115.0.0.0/8-j -s116.0.0.0/8-j -s117.0.0.0/8-j -s118.0.0.0/8-j -s119.0.0.0/8-j -s 120.0.0.0/8-j -s 121.0.0.0/8-j -s 122.0.0.0/8-j -s 123.0.0.0/8-j -s 124.0.0.0/8-j -s 125.0.0.0/8-j -s 126.0.0.0/8-j

DENY DENY DENY DENY DENY DENY DENY DENY DENY DENY DENY DENY DENY DENY DENY

#217: 11011001 -15 includes 216 - need 217-219 spelled out ipchains -A input -i $EXTERNAL_INTERFACE -s 217.0.0.0/8 -j DENY -I ipchains -A input -i $EXTERNAL_INTERFACE -s 218.0.0.0/8 -j DENY -I ipchains -A input -i $EXTERNAL_INTERFACE -s 219.0.0.0/8 -j DENY -I
#223: 11011111 -16 masks 220-223
ipchains -A input -i $EXTERNAL_INTERFACE -s 220.0.0.0/6 -j DENY -I

Страниц: 1 2 3 4 5 6 7 8 9 10

« Some explanation of rules used in the firewall script files
Configuration of the “/etc/rc.d/init.d/firewall” script file for the Mail Server »