Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

IPTABLES problem

Status
Not open for further replies.

iSeriesCodePoet

Programmer
Jan 11, 2001
1,373
US
I am close on getting my firewall working. I have one task left, blocking access from eth1 (10.1.1.1) to eth2 (10.1.2.1) and vise versa.

I am using IPTables for a firewall, and have port forwarding working between eth0 and the other 2, but I don't want the two internal NICs talking. Basically, I want create a DMZ (but that isn't the purpose).

What I have in firewall rules now, that doesn't seem to work is in IPtable 'filter', chain FORWORD, Drop If
input interface is *eth2* and output interface is *eth1.* I have a second for the other way. Unfortunatly, this does not seem to work as I can browse to a webserver running on the other network, and I can ping it as well.

Does anyone know how to help? Thanks,

iSeriesCodePoet
iSeries Programmer/Lawson Software Administrator
[pc2]
See my progress to converting to linux. The Programmer's Knowledge Base ->
 
You might try running tcpdump to see what's really going on. I'm not enough of an expert to see what's wrong- your idea looks right to me. Also check the order of rules to ensure that there's not a higher-level rule which is allowing the traffic. You could add some LOG rules with different log-prefix's to see how the traffic is actually flowing.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top