Log in

Bekijk de volledige versie : Secure settings (firewall, iptables and vsftpd)



absolon
04-08-2008, 16:25
Hi!

My setup:
- Oleg firmware
- Vsftpd from ipkg pacakge.

Problem
I have no access to vsftpd from outside if firewall in WebAdmin is enabled. So the only one way to have access is to disable firewall?
OK, let's say I will disable it. I'd like to use iptables instead. But what rules should I put in post-firewall to be still protected?

Is it enough?


iptables -P FORWARD DROP
iptables -P INPUT DROP
iptables -A INPUT --protocol tcp --destination-port 20:21 -j ACCEPT

1. All what I want is to be protected as much as possible
2. Have access to ftp from outside.

By the way, I made small test (PC Flank website) with firewall (in Webadmin) enabled/disabled.

With endabled:
- all ports are reported as stealthed

With firewall disabled + iptables rules shown above:
- some ports are reported as closed
- some 80, 21, 23, 139 are open (I don't have www server!, why port 80 is open? hmm...)

darius
04-08-2008, 17:54
Hi,

me too interested in iptables and especially in traffic shaping, traffic control
http://tcng.sourceforge.net/
http://www.trekweb.com/~jasonb/articles/traffic_shaping/scenarios.html
http://www.topwebhosts.org/tools/traffic-control.php
http://www.novell.com/communities/node/4995/adjusting-iptables-rule-server-health-monitoring

http://www.unix.com/shell-programming-scripting/34578-control-over-shell-script.html

I copy&pasted iptables/ firewall script from another thread.

Still looking for a shell script solution to control Wifi traffic - tc (too complicated) wshaper (too complicated) ..
any other basic solution ?


Darius


Hi!

My setup:
- Oleg firmware
- Vsftpd from ipkg pacakge.

Problem
I have no access to vsftpd from outside if firewall in WebAdmin is enabled. So the only one way to have access is to disable firewall?
OK, let's say I will disable it. I'd like to use iptables instead. But what rules should I put in post-firewall to be still protected?

Is it enough?



1. All what I want is to be protected as much as possible
2. Have access to ftp from outside.

By the way, I made small test (PC Flank website) with firewall (in Webadmin) enabled/disabled.

With endabled:
- all ports are reported as stealthed

With firewall disabled + iptables rules shown above:
- some ports are reported as closed
- some 80, 21, 23, 139 are open (I don't have www server!, why port 80 is open? hmm...)