Iptables Firewall Stateless vs Statefull on Router

Iptables Firewall Stateless vs Statefull on Router
Task: Create the firewall rule for IP 1.1.1.1 can access ssh server on 2.2.2.2

2 ways:

1. Stateless
#iptables -P FORWARD DROP
#iptables -A FORWARD -p tcp --dport 22 -s 1.1.1.1 -d 2.2.2.2 -j ACCEPT
#iptables -A FORWARD -p tcp --sport 22 -s 2.2.2.2 -d 1.1.1.1 -j ACCEPT

or

2. Statefull (recommended)
#iptables -P FORWARD DROP
#iptables -A FORWARD -p tcp -m state --state ESTABLISHED,RELATED -j ACCEPT
#iptables -A FORWARD -p tcp --dport 22 -s 1.1.1.1 -d 2.2.2.2 -j ACCEPT

Komentar

Postingan populer dari blog ini

Cara memahami dan menghafal model OSI dengan analogi

Pembahasan IT Network Systems Administration Module A DNS (Forward Zone, Reverse Zone, CNAME, MX, Split View)

Table of Contents