facebraker
New Member
Hallo,
ich bin gerade dabei den neuen Root-Server einzurichten.
Natürlich mit Firewall, leider funktioniert mein altes Skript nicht mehr.
Es kommt der Fehler:
Hier ist mein Skript:
Ich wollte es Step-by-Step manuell durchgehen, aber ich säge mir ja beim Remotezugriff immer selber den Ast ab und muss immer rebooten :-(
Kenn jemand das Problem?
Der neue Server ist ein 64Bit, der alte war ein 32Bit, ich habe auch gesehen es gibt 2 iptables Pakete, zusätzlich noch ein i386=32Bit, hat es damit zu tun?
Danke für Eure Hilfe.
Gruß Alex
ich bin gerade dabei den neuen Root-Server einzurichten.
Natürlich mit Firewall, leider funktioniert mein altes Skript nicht mehr.
Es kommt der Fehler:
Bad argument `eth0'
Try `iptables -h' or 'iptables --help' for more information.
Hier ist mein Skript:
Code:
#!/bin/sh
#
IPTABLES="/sbin/iptables"
OUTSIDE=eth0
#
# Clear out any existing firewall rules, and any chains that might have
# been created. Then set the default policies.
#
$IPTABLES -F
$IPTABLES -F INPUT
$IPTABLES -F OUTPUT
$IPTABLES -X
$IPTABLES -P INPUT DROP
$IPTABLES -P OUTPUT ACCEPT
#
# Begin setting up the rulesets. First define some rule chains to handle
# exception conditions. These chains will receive packets that we aren't
# willing to pass. Limiters on logging are used so as to not to swamp the
# firewall in a DOS scenario.
#
# silent - Just dop the packet
# tcpflags - Log packets with bad flags, most likely an attack
# firewalled - Log packets that that we refuse, possibly froman attack
#
$IPTABLES -N silent
$IPTABLES -A silent -j DROP
$IPTABLES -N tcpflags
$IPTABLES -A tcpflags -m limit --limit 15/minute -j LOG --log-prefix TCPflags:
$IPTABLES -A tcpflags -j DROP
$IPTABLES -N firewalled
$IPTABLES -A firewalled -m limit --limit 15/minute -j LOG --log-prefix Firewalled:
$IPTABLES -A firewalled -j DROP
#
# These are all TCP flag combinations that should never, ever, occur in the
# wild. All of these are illegal combinations that are used to attack a box
# in various ways.
#
$IPTABLES -A INPUT -p tcp --tcp-flags ALL FIN,URG,PSH -j tcpflags
$IPTABLES -A INPUT -p tcp --tcp-flags ALL ALL -j tcpflags
$IPTABLES -A INPUT -p tcp --tcp-flags ALL SYN,RST,ACK,FIN,URG -j tcpflags
$IPTABLES -A INPUT -p tcp --tcp-flags ALL NONE -j tcpflags
$IPTABLES -A INPUT -p tcp --tcp-flags SYN,RST SYN,RST -j tcpflags
$IPTABLES -A INPUT -p tcp --tcp-flags SYN,FIN SYN,FIN -j tcpflags
#
# Allow selected ICMP types and drop the rest.
#
$IPTABLES -A INPUT -p icmp --icmp-type 0 -j ACCEPT
$IPTABLES -A INPUT -p icmp --icmp-type 3 -j ACCEPT
$IPTABLES -A INPUT -p icmp --icmp-type 11 -j ACCEPT
$IPTABLES -A INPUT -p icmp --icmp-type 8 -m limit --limit 1/second -j ACCEPT
$IPTABLES -A INPUT -p icmp -j firewalled
#
# Allow selected TCP ports
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 20 -j ACCEPT #FTP
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 21 -j ACCEPT #FTP
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 22 -j ACCEPT #SSH
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 25 -j ACCEPT #SMTP
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 80 -j ACCEPT #HTTP
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 8443 -j ACCEPT #Plesk
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 443 -j ACCEPT #HTTPS
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 465 -j ACCEPT #SMTP-SSL
$IPTABLES -A INPUT -i $OUTSIDE -p UDP --dport 465 -j ACCEPT #SMTP-SSL
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 993 -j ACCEPT #IMAP-SSL
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 995 -j ACCEPT #POP3-SSL
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 3306 -j ACCEPT #MYSQL
$IPTABLES -A INPUT -i $OUTSIDE -p UDP --dport 10000 -j ACCEPT #Webmin
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 993 -j ACCEPT #IMAP-SSL
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 143 -j ACCEPT #IMAP
#$IPTABLES -A INPUT -i $OUTSIDE -p UDP --dport 5060 -j ACCEPT
#$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 5060 -j ACCEPT
#$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 6000 -j ACCEPT
#$IPTABLES -A INPUT -i $OUTSIDE -p UDP --dport 6000 -j ACCEPT
#$IPTABLES -A INPUT -i $OUTSIDE -p UDP --dport 6277 -j ACCEPT #DCC
$IPTABLES -A INPUT -p udp -m udp --dport 1024:65535 --sport 6277 -j ACCEPT #DCC
#
# The loopback interface is inheritly trustworthy. Don't disable it or
# a number of things on the firewall will break.
#
$IPTABLES -A INPUT -i lo -j ACCEPT
#
# Allow packets that are part of an established connection to pass
# through the firewall. This is required for normal Internet activity
# by inside clients.
#
$IPTABLES -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
#
# Silently drop and SMB traffic. We've slipped the surly bonds of windows
# and are dancing on the silvery wings of Linux, so block that windows trash.
#
$IPTABLES -A INPUT -p udp --sport 137 --dport 137 -j silent
$IPTABLES -A INPUT -p udp --sport 138 --dport 138 -j silent
$IPTABLES -A INPUT -p udp --sport 68 --dport 67 -j silent
$IPTABLES -A INPUT -p udp --sport 67 --dport 68 -j silent
#
# Anything that hasn't already matched gets logged and then dropped.
#
$IPTABLES -A INPUT -j firewalled
# block chain starts here
$IPTABLES -N block
$IPTABLES -A INPUT -j block
$IPTABLES -A block -m state --state RELATED,ESTABLISHED -j ACCEPT
$IPTABLES -A block -i ! $OUTSIDE -m state --state NEW -j ACCEPT
$IPTABLES -A block -j DROP
Ich wollte es Step-by-Step manuell durchgehen, aber ich säge mir ja beim Remotezugriff immer selber den Ast ab und muss immer rebooten :-(
Kenn jemand das Problem?
Der neue Server ist ein 64Bit, der alte war ein 32Bit, ich habe auch gesehen es gibt 2 iptables Pakete, zusätzlich noch ein i386=32Bit, hat es damit zu tun?
Danke für Eure Hilfe.
Gruß Alex