Netfilter / IPTables Question

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Dear all,

I?m new to iptables / netfilter and I have the problem that i need to
configure a linux System (Debian-PowerPC x64) and I don?t know how to do so
? :(

Here?s the System:

Eth0:     disabled
Eth1:     disabled
Eth2:     IP: 10.0.0.4                         Subnet:
255.255.255.128              Gateway / DNS: 10.0.0.1
                                            Interface to the Internet
Eth3:     IP: 192.168.0.6                  Subnet: 255.255.254.0   Gateway /
DNS: the System itself                           This is the IP Interface to
the schools Network (for Students and stuff)
Eth4:     IP: 192.168.2.2                  Subnet 255.255.254.0    Gateway /
DNS: the System itself                           This is the IP Interface to
the Network of the schools Administration
Eth5:     IP: 172.16.0.20                  Subnet: 255.255.255.0   Gateway /
DNS: none                                                  This is the IP
Interface to the Cisco Management Network

The System is running the following Services:

Bound to the IP of the Eth3 Interface:                  DNS, Webmin,
Usermin, LDAP, Squid, NTP, DHCP, Nagios, Apache, SSH
Bound to the IP of the Eth4 Interface:                  DNS, Webmin,
Usermin, LDAP, Squid, NTP, DHCP, Nagios, Apache, SSH
Bound to the IP of the Eth5 Interface:                  Nagios, SSH, Apache

What should be done:                  Requests from
Eth2:                     None, cause this is only the Interface towards the
Internet
                                                               Requests from
Eth3:                     Could reach every Port on the Host itself, but
none in the other networks, and every user from the net should have access
to DNS, NTP and UDP / TCP Port 3339 on every Host on the internet;
everything else should be accessable via squid
                                                               Requests from
Eth4:                     Mail Services (IMAP, POP3, SMTP) and DNS, NTP is
permitted to be accessed on the net, everything else should be accessable
via squid 
                                                              
Eth5:                                                    Not accessable from
any Network, only be the host itself.


Is this possible?

Thanks in advance,

Markus


ÿôèº{.nÇ+?·?®?­?+%?Ëÿ±éݶ¥?wÿº{.nÇ+?·§z×â?׫þ)í?æèw*jg¬±¨¶????Ý¢jÿ¾«þG«?éÿ¢¸¢·¦j:+v?¨?wèjØm¶?ÿþø¯ù®w¥þ?àþf£¢·h??â?úÿ?Ù¥



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux