12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

478CHAPTER 24Configuring a FirewallTIPLog messages for IPTables are controlled by syslog and go to /var/log/messages bydefault.Selecting a Table and Command for IPTablesThe first part of an IPTables rule is defining the table with the -t option:iptables -t ...Choose from the following tables:. filter: Default table used if -t is not specified. Its predefined chains areINPUT, FORWARD, and OUTPUT.. nat: Use when a packet tries to create a new connection. Its predefined chains arePREROUTING, OUTPUT, and POSTROUTING.. mangle: Use for specialized packet altering such as changing the destination ofthe packet. Its predefined chains are PREROUTING, OUTPUT, INPUT, FORWARD, andPOSTROUTING.. raw: Use for exempting packets from connection tracking when the NOTRACK target isused. Its predefined chains are PREROUTING and OUTPUT.Each rule must contain only one of the commands listed in Table 24.1 unless otherwisespecified. The command should follow the table definition:iptables -t -A ...TABLE 24.1 IPTables CommandsIPTables CommandDescription-A Append rule to the end of the chain.-D Delete rule. The can be the rule number,with the count starting at 1.-I Insert a rule at a specific point in the chain.-R Replace a rule at a specific point in the chain.-L List all rules in the chain. The -t optioncan be used to display rules for a given table.-F Delete, or flush, all the rules in the chain.-Z Set the packet and byte counters to zero in aspecific chain or in all chains if no chain is given.-N Add a new chain. Name must be unique.-X Delete a given chain. Before a chain can bedeleted, it cannot be referenced by any rules, andthe chain must not contain any rules.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!