iptables - Skript auf Ubuntu 12.04 LTS funktioniert nicht



facebraker

New Member
Hallo,

ich bin gerade dabei den neuen Root-Server einzurichten.
Natürlich mit Firewall, leider funktioniert mein altes Skript nicht mehr.

Es kommt der Fehler:
Bad argument `eth0'
Try `iptables -h' or 'iptables --help' for more information.

Hier ist mein Skript:

Code:
#!/bin/sh
#
IPTABLES="/sbin/iptables"
OUTSIDE=eth0
#
# Clear out any existing firewall rules, and any chains that might have
# been created. Then set the default policies.
#
$IPTABLES -F
$IPTABLES -F INPUT
$IPTABLES -F OUTPUT
$IPTABLES -X
$IPTABLES -P INPUT DROP
$IPTABLES -P OUTPUT ACCEPT
#
# Begin setting up the rulesets. First define some rule chains to handle
# exception conditions. These chains will receive packets that we aren't
# willing to pass. Limiters on logging are used so as to not to swamp the
# firewall in a DOS scenario.
#
# silent        - Just dop the packet
# tcpflags      - Log packets with bad flags, most likely an attack
# firewalled    - Log packets that that we refuse, possibly froman attack
#
$IPTABLES -N silent
$IPTABLES -A silent -j DROP

$IPTABLES -N tcpflags
$IPTABLES -A tcpflags -m limit --limit 15/minute -j LOG --log-prefix TCPflags:
$IPTABLES -A tcpflags -j DROP

$IPTABLES -N firewalled
$IPTABLES -A firewalled -m limit --limit 15/minute -j LOG --log-prefix Firewalled:
$IPTABLES -A firewalled -j DROP
#
# These are all TCP flag combinations that should never, ever, occur in the
# wild. All of these are illegal combinations that are used to attack a box
# in various ways.
#
$IPTABLES -A INPUT -p tcp --tcp-flags ALL FIN,URG,PSH -j tcpflags
$IPTABLES -A INPUT -p tcp --tcp-flags ALL ALL -j tcpflags
$IPTABLES -A INPUT -p tcp --tcp-flags ALL SYN,RST,ACK,FIN,URG -j tcpflags
$IPTABLES -A INPUT -p tcp --tcp-flags ALL NONE -j tcpflags
$IPTABLES -A INPUT -p tcp --tcp-flags SYN,RST SYN,RST -j tcpflags
$IPTABLES -A INPUT -p tcp --tcp-flags SYN,FIN SYN,FIN -j tcpflags
#
# Allow selected ICMP types and drop the rest.
#
$IPTABLES -A INPUT -p icmp --icmp-type 0 -j ACCEPT
$IPTABLES -A INPUT -p icmp --icmp-type 3 -j ACCEPT
$IPTABLES -A INPUT -p icmp --icmp-type 11 -j ACCEPT
$IPTABLES -A INPUT -p icmp --icmp-type 8 -m limit --limit 1/second -j ACCEPT
$IPTABLES -A INPUT -p icmp -j firewalled
#
# Allow selected TCP ports
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 20 -j ACCEPT      #FTP
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 21 -j ACCEPT      #FTP
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 22 -j ACCEPT      #SSH
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 25 -j ACCEPT      #SMTP
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 80 -j ACCEPT      #HTTP
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 8443 -j ACCEPT    #Plesk
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 443 -j ACCEPT     #HTTPS
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 465 -j ACCEPT     #SMTP-SSL
$IPTABLES -A INPUT -i $OUTSIDE -p UDP --dport 465 -j ACCEPT     #SMTP-SSL
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 993 -j ACCEPT     #IMAP-SSL
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 995 -j ACCEPT     #POP3-SSL
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 3306 -j ACCEPT    #MYSQL
$IPTABLES -A INPUT -i $OUTSIDE -p UDP --dport 10000 -j ACCEPT   #Webmin
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 993 -j ACCEPT     #IMAP-SSL
$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 143 -j ACCEPT     #IMAP

#$IPTABLES -A INPUT -i $OUTSIDE -p UDP --dport 5060 -j ACCEPT
#$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 5060 -j ACCEPT
#$IPTABLES -A INPUT -i $OUTSIDE -p TCP --dport 6000 -j ACCEPT
#$IPTABLES -A INPUT -i $OUTSIDE -p UDP --dport 6000 -j ACCEPT
#$IPTABLES -A INPUT -i $OUTSIDE -p UDP --dport 6277 -j ACCEPT   #DCC

$IPTABLES -A INPUT -p udp -m udp --dport 1024:65535 --sport 6277 -j ACCEPT #DCC
#
# The loopback interface is inheritly trustworthy. Don't disable it or
# a number of things on the firewall will break.
#
$IPTABLES -A INPUT -i lo -j ACCEPT
#
# Allow packets that are part of an established connection to pass
# through the firewall. This is required for normal Internet activity
# by inside clients.
#
$IPTABLES -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
#
# Silently drop and SMB traffic. We've slipped the surly bonds of windows
# and are dancing on the silvery wings of Linux, so block that windows trash.
#
$IPTABLES -A INPUT -p udp --sport 137 --dport 137 -j silent
$IPTABLES -A INPUT -p udp --sport 138 --dport 138 -j silent
$IPTABLES -A INPUT -p udp --sport 68 --dport 67 -j silent
$IPTABLES -A INPUT -p udp --sport 67 --dport 68 -j silent
#
# Anything that hasn't already matched gets logged and then dropped.
#
$IPTABLES -A INPUT -j firewalled

# block chain starts here
$IPTABLES -N block
$IPTABLES -A INPUT -j block
$IPTABLES -A block -m state --state RELATED,ESTABLISHED -j ACCEPT
$IPTABLES -A block -i ! $OUTSIDE -m state --state NEW -j ACCEPT
$IPTABLES -A block -j DROP

Ich wollte es Step-by-Step manuell durchgehen, aber ich säge mir ja beim Remotezugriff immer selber den Ast ab und muss immer rebooten :-(

Kenn jemand das Problem?

Der neue Server ist ein 64Bit, der alte war ein 32Bit, ich habe auch gesehen es gibt 2 iptables Pakete, zusätzlich noch ein i386=32Bit, hat es damit zu tun?


Danke für Eure Hilfe.

Gruß Alex
 
Ich tippe auf
Code:
$IPTABLES -A block -i ! $OUTSIDE -m state --state NEW -j ACCEPT

Bereits in der iptables-Version bei Ubuntu 10.04 wurde diese Form der Negation als deprecated angemerkt.
 
Hallo,

ich konnte folgende Zeile identifizieren:

Code:
iptables -A block -i ! eth0 -m state --state NEW -j ACCEPT

da bricht er mit

Bad argument `eth0'
Try `iptables -h' or 'iptables --help' for more information.

ab.

Hat jemand einen Tipp für mich?

Gruß Alex
 
Den Tipp dazu hat dir die Fehlermeldung schon geliefert.
Code:
iptables -h
bzw. ein Blick in die man-Page offenbaren, dass

Code:
       [!] -i, --in-interface name
              Name  of  an interface via which a packet was received (only for
              packets entering the  INPUT,  FORWARD  and  PREROUTING  chains).
              When  the  "!"  argument  is used before the interface name, the
              sense is inverted.  If the interface name ends in  a  "+",  then
              any  interface  which begins with this name will match.  If this
              option is omitted, any interface name will match.
 
Hallo wstürmer, du hattest recht.

Ich habe meine Probleme, was mir die Chain "block" sagt, bzw. wie ich es so umschreiben kann, dass ich das eth0 nicht negieren muss?

Gruß Alex
 
Ersetze

Code:
$IPTABLES -A block -i ! $OUTSIDE -m state --state NEW -j ACCEPT

durch

Code:
$IPTABLES -A block ! -i $OUTSIDE -m state --state NEW -j ACCEPT


Die Negation muss vor die Option, nicht zwischen Option und Argument.
 
Ja klar iptables -h hilft aber wenn man nicht weiß welche Zeile er anmeckert ist es auch mühselig :-(

Ich müßte doch nur lo angeben, andere Interfaces habe ich doch nicht?

Gruß Alex
 
Back
Top