[Nottingham] iptables arguments

Jason Irwin jasonirwin73 at gmail.com
Thu Nov 27 10:09:11 UTC 2014


On 27/11/14 09:30, Mike Cardwell wrote:
> Those rules mean that any traffic on ports 23, 22, 80 and 443 are blocked.
Cool, that's what I thought.

> Everything else follows the default policy, which is probably accept.
> Is the web admin interface on one of those 4 ports?
Yup, it's on port 80 as one would expect. I wonder if a following rule
was undoing the good work...will have to check
I actually prefer the new way. Deny everything and then only let
essentials through.

> "iptables -I" inserts a rule at the beginning. "iptables -A" appends a rule
> at the end.
Oh FFS. face/palm.

> So if you run those 4 commands in that order, the list is the
> reverse of what you think it is. "iptables -nvL" to see the rules that are
> currently in use.
Yes, clear now. Thank you very much.

-- 
╔═════════════╦══════════════════════════════════════════╗
║ Jason Irwin ║ OpenPGP (GPG/PGP) Public Key: 0xD0C592B1 ║
║             ║ Import from hkp://pgp.mit.edu            ║
╚═════════════╩══════════════════════════════════════════╝



More information about the Nottingham mailing list