Iptables Firewall Stateless vs Statefull on Router
Iptables Firewall Stateless vs Statefull on Router
Task: Create the firewall rule for IP 1.1.1.1 can access ssh server on 2.2.2.2
2 ways:
1. Stateless
#iptables -P FORWARD DROP
#iptables -A FORWARD -p tcp --dport 22 -s 1.1.1.1 -d 2.2.2.2 -j ACCEPT
#iptables -A FORWARD -p tcp --sport 22 -s 2.2.2.2 -d 1.1.1.1 -j ACCEPT
or
2. Statefull (recommended)
#iptables -P FORWARD DROP
#iptables -A FORWARD -p tcp -m state --state ESTABLISHED,RELATED -j ACCEPT
#iptables -A FORWARD -p tcp --dport 22 -s 1.1.1.1 -d 2.2.2.2 -j ACCEPT
Task: Create the firewall rule for IP 1.1.1.1 can access ssh server on 2.2.2.2
2 ways:
1. Stateless
#iptables -P FORWARD DROP
#iptables -A FORWARD -p tcp --dport 22 -s 1.1.1.1 -d 2.2.2.2 -j ACCEPT
#iptables -A FORWARD -p tcp --sport 22 -s 2.2.2.2 -d 1.1.1.1 -j ACCEPT
or
2. Statefull (recommended)
#iptables -P FORWARD DROP
#iptables -A FORWARD -p tcp -m state --state ESTABLISHED,RELATED -j ACCEPT
#iptables -A FORWARD -p tcp --dport 22 -s 1.1.1.1 -d 2.2.2.2 -j ACCEPT
Komentar