<?xml version="1.0" encoding="iso-8859-1"?>
<rss version="2.0">
<channel>
  <title>Linux Format forums</title>
  <link>http://linuxformat.com/forums/index.php</link>
  <description>Help, discussion, magazine feedback and more</description>
  <language>english</language>
  <copyright>(c) Copyright Thu May 23, 2013 8:00 pm by Linux Format forums</copyright>
  <managingEditor>webmaster@linuxformat.com</managingEditor>
  <webMaster>webmaster@linuxformat.com</webMaster>
  <pubDate>Thu May 23, 2013 8:00 pm</pubDate>
  <lastBuildDate>Thu May 23, 2013 8:00 pm</lastBuildDate>
  <docs>http://backend.userland.com/rss</docs>
  <generator>phpBB2 RSS Syndication Mod by Lucas</generator>
  <ttl>1</ttl>

  <image>
    <title>Linux Format forums</title>
    <url></url>
    <link>http://linuxformat.com/forums/</link>
    <description>Help, discussion, magazine feedback and more</description>
  </image>

                                      <item>
                                        <title>RE: Rules incorporating subnet addresses</title>
                                        <link>http://linuxformat.com/forums/viewtopic.php?p=2175#2175</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=162'&gt;Nigel&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Mon May 23, 2005 11:18 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      I'm guessing that the 192.16.2.20 was a typo as everything else in the post refers to 172.16.2.120...</description>
                                        <comments>http://linuxformat.com/forums/viewtopic.php?p=2175#2175</comments>
                                        <author>Nigel</author>
                                        <pubDate>Mon May 23, 2005 11:18 am</pubDate>
                                        <guid isPermaLink="true">http://linuxformat.com/forums/viewtopic.php?p=2175#2175</guid>
                                      </item>
                                      <item>
                                        <title>RE: Rules incorporating subnet addresses</title>
                                        <link>http://linuxformat.com/forums/viewtopic.php?p=2170#2170</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=-1'&gt;Anonymous&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Mon May 23, 2005 10:28 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      Hmmm. but what concerns me here is how does a PC with an IP address like 192.16.2.20 succeed at all in communicating on a subnet id of 172.16.2.0 ??? typo in subnet id ?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Once that aspect is sorted, the challenge is to figure out how to test it correctly......if you have access to a second PC, best to set up a slow old dial-up connection to the Internet so you can &quot;pretend&quot; to be someone on the &quot;public&quot; side of the FW.&lt;br /&gt;
&lt;br /&gt;
CharlieS.</description>
                                        <comments>http://linuxformat.com/forums/viewtopic.php?p=2170#2170</comments>
                                        <author>Anonymous</author>
                                        <pubDate>Mon May 23, 2005 10:28 am</pubDate>
                                        <guid isPermaLink="true">http://linuxformat.com/forums/viewtopic.php?p=2170#2170</guid>
                                      </item>
                                      <item>
                                        <title>RE: Rules incorporating subnet addresses</title>
                                        <link>http://linuxformat.com/forums/viewtopic.php?p=2159#2159</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=-1'&gt;Anonymous&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Mon May 23, 2005 12:46 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      Thanks Nigel&lt;br /&gt;
&lt;br /&gt;
That makes sense!</description>
                                        <comments>http://linuxformat.com/forums/viewtopic.php?p=2159#2159</comments>
                                        <author>Anonymous</author>
                                        <pubDate>Mon May 23, 2005 12:46 am</pubDate>
                                        <guid isPermaLink="true">http://linuxformat.com/forums/viewtopic.php?p=2159#2159</guid>
                                      </item>
                                      <item>
                                        <title>RE: Rules incorporating subnet addresses</title>
                                        <link>http://linuxformat.com/forums/viewtopic.php?p=2156#2156</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=162'&gt;Nigel&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Sun May 22, 2005 11:24 pm&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      Um, I may be misreading this, but why would traffic from one machine on the subnet to another machine on the same subnet be going through your firewall at all ? You need to set up something on 172.16.2.120 itself to drop all incoming ssh connections.&lt;br /&gt;
&lt;br /&gt;
AFAIK the firewall will only affect connections that use that machine as a router (ie it needs to come in on one of your ethernet cards and go out on the other), or stuff that comes in on either card destined for the firewall box itself.</description>
                                        <comments>http://linuxformat.com/forums/viewtopic.php?p=2156#2156</comments>
                                        <author>Nigel</author>
                                        <pubDate>Sun May 22, 2005 11:24 pm</pubDate>
                                        <guid isPermaLink="true">http://linuxformat.com/forums/viewtopic.php?p=2156#2156</guid>
                                      </item>
                                      <item>
                                        <title>Rules incorporating subnet addresses</title>
                                        <link>http://linuxformat.com/forums/viewtopic.php?p=2145#2145</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=-1'&gt;Anonymous&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Sun May 22, 2005 6:24 pm&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      Does anyone know the answer to this one???&lt;br /&gt;
&lt;br /&gt;
I'm configuring a firewall that's got an eth0 link to the internet &amp;amp; an eth1 link to an internal subnet (172.16.2.0).  &lt;br /&gt;
&lt;br /&gt;
I've put in this rule to stop all ssh access to a PC (192.16.2.120) on the subnet via the firewall:&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;iptables -A FORWARD -p tcp -s 0/0 -d 172.16.2.120 --dport 22 -j DROP&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
however, this rule is still allowing other PCs on the subnet to connect to the PC.  I've also tried the following rules, even to the point of specify an individual source PC on the subnet &amp;amp; dropping all ssh traffic to the destination PC &amp;amp; changing the FORWARD policy to DROP:&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold&quot;&gt;iptables -A FORWARD -p tcp -s 172.16.2.0/24 -d 172.16.2.120 --dport 22 -j DROP&lt;br /&gt;
iptables -A FORWARD -p tcp -s 172.16.2.220 -d 172.16.2.120 --dport 22 -j DROP&lt;br /&gt;
iptables -A FORWARD -p tcp -d 172.16.2.120 --dport -j DROP&lt;br /&gt;
iptables -P FORWARD DROP&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
Yet i can still contact the destination PC from another PC on the subnet.  I've read &amp;amp; read &amp;amp; read till I'm blue in the face &amp;amp; can't for the life in me figure out why this isn't working!!&lt;br /&gt;
&lt;br /&gt;
Does anybody have any suggestions???&lt;br /&gt;
&lt;br /&gt;
Cheers</description>
                                        <comments>http://linuxformat.com/forums/viewtopic.php?p=2145#2145</comments>
                                        <author>Anonymous</author>
                                        <pubDate>Sun May 22, 2005 6:24 pm</pubDate>
                                        <guid isPermaLink="true">http://linuxformat.com/forums/viewtopic.php?p=2145#2145</guid>
                                      </item></channel></rss>