firewall

Derek Trotter expat.arizonan at gmail.com
Mon Aug 6 23:06:13 MST 2012


Recently I got dsl and decided to have my linux box pass on traffic to 
my windows box rather than buying a firewall.  I did the research online 
and figured out how to make everything work like I wanted. Is there 
anything I've done wrong?  Does anyone have any suggestions to improve 
it?  Below is what I put into rc.local including comments in case I 
forget later what each part does.  Wallace is the linux box.  Ladmo is 
the windows box.  Thanks.

iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
iptables -A FORWARD -i eth0 -o eth1 -m state --state RELATED,ESTABLISHED 
-j ACCEPT
iptables -A FORWARD -i eth1 -o eth0 -j ACCEPT
# The 3 above allow for nat and forwarding to Ladmo.  This allows me to 
do stuff online from Ladmo.

iptables -A PREROUTING -t nat -i eth0 -p tcp --dport 40998 -j DNAT --to 
192.168.0.2:40998
# Allows bittorrent clients on the net to contact mine.

iptables -A OUTPUT -o eth0 -p tcp --dport 80 -m state --state 
NEW,ESTABLISHED -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --sport 80 -m state --state ESTABLISHED 
-j ACCEPT
# Allows me to surf the web from Wallace.

iptables -A OUTPUT -o eth0 -p tcp --dport 53 -m state --state 
NEW,ESTABLISHED -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --sport 53 -m state --state ESTABLISHED 
-j ACCEPT
iptables -A OUTPUT -o eth0 -p udp --dport 53 -m state --state 
NEW,ESTABLISHED -j ACCEPT
iptables -A INPUT -i eth0 -p udp --sport 53 -m state --state ESTABLISHED 
-j ACCEPT
#allows dns to work on Wallace.

iptables -A INPUT -i eth0 -j DROP
#Drops unwanted incoming packets.


More information about the PLUG-discuss mailing list