<?xml version="1.0" encoding="UTF-8"?><rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
> <channel><title>Comments on: CentOS / Redhat Iptables Firewall Configuration Tutorial</title> <atom:link href="http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/feed/" rel="self" type="application/rss+xml" /><link>http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/</link> <description>Every answer asks a more beautiful question.</description> <lastBuildDate>Fri, 10 Feb 2012 19:55:56 +0000</lastBuildDate> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <item><title>By: Jesus</title><link>http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/#comment-66744</link> <dc:creator>Jesus</dc:creator> <pubDate>Thu, 12 Jan 2012 22:04:13 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=5721#comment-66744</guid> <description>Really useful stuff. Thanks a lot</description> <content:encoded><![CDATA[<p>Really useful stuff. Thanks a lot</p> ]]></content:encoded> </item> <item><title>By: adep</title><link>http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/#comment-66558</link> <dc:creator>adep</dc:creator> <pubDate>Mon, 09 Jan 2012 18:48:03 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=5721#comment-66558</guid> <description>Most distribution kernels have it compiled in (/module) at the very least. But that doesn&#039;t mean that the rules help anything. Also, a lot of distros like ubuntu use a gui like ufw which is still using iptables.</description> <content:encoded><![CDATA[<p>Most distribution kernels have it compiled in (/module) at the very least. But that doesn&#8217;t mean that the rules help anything. Also, a lot of distros like ubuntu use a gui like ufw which is still using iptables.</p> ]]></content:encoded> </item> <item><title>By: Haekon</title><link>http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/#comment-65898</link> <dc:creator>Haekon</dc:creator> <pubDate>Thu, 22 Dec 2011 08:22:50 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=5721#comment-65898</guid> <description>&quot; It is included as part of the Linux distribution and it is activated by default.&quot;
fail....Each distro is its own, and some disable this.</description> <content:encoded><![CDATA[<p>&#8221; It is included as part of the Linux distribution and it is activated by default.&#8221;</p><p>fail&#8230;.Each distro is its own, and some disable this.</p> ]]></content:encoded> </item> <item><title>By: JD</title><link>http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/#comment-65584</link> <dc:creator>JD</dc:creator> <pubDate>Tue, 13 Dec 2011 13:34:05 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=5721#comment-65584</guid> <description>GREAT article on Netfilter, there are several good books on amazon&#039;s website that can help with creating custom chains as well.
I create a custom chain called &#039;uw&#039; for unwanted, it includes all the DROP&#039;s for rogue countries and/or ISP&#039;s/Hosting companies.
It is critical that you do not allow rogue traffic to your server(s), it should be dropped and and not allowed.</description> <content:encoded><![CDATA[<p>GREAT article on Netfilter, there are several good books on amazon&#8217;s website that can help with creating custom chains as well.</p><p>I create a custom chain called &#8216;uw&#8217; for unwanted, it includes all the DROP&#8217;s for rogue countries and/or ISP&#8217;s/Hosting companies.</p><p>It is critical that you do not allow rogue traffic to your server(s), it should be dropped and and not allowed.</p> ]]></content:encoded> </item> <item><title>By: James</title><link>http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/#comment-48842</link> <dc:creator>James</dc:creator> <pubDate>Tue, 17 Aug 2010 18:13:05 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=5721#comment-48842</guid> <description>But it does seem to alleviate the DDOS attacks today. I only worry that some of my regular users got blocked by mistake.
So by default, why there is not an iptables file? I used save to generate one.
But then where this file exist if it doesn&#039;t exist? (default)</description> <content:encoded><![CDATA[<p>But it does seem to alleviate the DDOS attacks today. I only worry that some of my regular users got blocked by mistake.</p><p>So by default, why there is not an iptables file? I used save to generate one.</p><p>But then where this file exist if it doesn&#8217;t exist? (default)</p> ]]></content:encoded> </item> <item><title>By: Vivek Gite</title><link>http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/#comment-48840</link> <dc:creator>Vivek Gite</dc:creator> <pubDate>Tue, 17 Aug 2010 16:22:31 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=5721#comment-48840</guid> <description>apf may add additional rules so you got 601 lines which is normal. However, on really busy servers you may get performance issue.</description> <content:encoded><![CDATA[<p>apf may add additional rules so you got 601 lines which is normal. However, on really busy servers you may get performance issue.</p> ]]></content:encoded> </item> <item><title>By: James</title><link>http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/#comment-48839</link> <dc:creator>James</dc:creator> <pubDate>Tue, 17 Aug 2010 16:17:24 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=5721#comment-48839</guid> <description>*mangle
:PREROUTING ACCEPT [20736884:2763721632]
:INPUT ACCEPT [20736866:2763715671]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [17305648:26071886184]
:POSTROUTING ACCEPT [17300520:26071636822]
-A PREROUTING -p tcp -m tcp --sport 21 -j TOS --set-tos 0x08
-A PREROUTING -p tcp -m tcp --sport 20 -j TOS --set-tos 0x08
-A PREROUTING -p tcp -m tcp --sport 80 -j TOS --set-tos 0x08
-A PREROUTING -p tcp -m tcp --sport 25 -j TOS --set-tos 0x10
-A PREROUTING -p tcp -m tcp --sport 110 -j TOS --set-tos 0x10
-A PREROUTING -p tcp -m tcp --sport 143 -j TOS --set-tos 0x10
-A PREROUTING -p tcp -m tcp --sport 512:65535 -j TOS --set-tos 0x00
-A POSTROUTING -p tcp -m tcp --dport 21 -j TOS --set-tos 0x08
-A POSTROUTING -p tcp -m tcp --dport 20 -j TOS --set-tos 0x08
-A POSTROUTING -p tcp -m tcp --dport 80 -j TOS --set-tos 0x08
-A POSTROUTING -p tcp -m tcp --dport 25 -j TOS --set-tos 0x10
-A POSTROUTING -p tcp -m tcp --dport 110 -j TOS --set-tos 0x10
-A POSTROUTING -p tcp -m tcp --dport 143 -j TOS --set-tos 0x10
-A POSTROUTING -p tcp -m tcp --dport 512:65535 -j TOS --set-tos 0x00
COMMIT
-A INPUT -s 0.0.0.0/255.0.0.0 -j DROP
-A INPUT -s 5.0.0.0/255.0.0.0 -j DROP
-A INPUT -s 23.0.0.0/255.0.0.0 -j DROP
-A INPUT -s 36.0.0.0/255.0.0.0 -j DROP
-A INPUT -s 37.0.0.0/255.0.0.0 -j DROP
-A INPUT -s 39.0.0.0/255.0.0.0 -j DROP
-A INPUT -s 42.0.0.0/255.0.0.0 -j DROP
-A INPUT -s 100.0.0.0/255.0.0.0 -j DROP
-A INPUT -s 102.0.0.0/255.0.0.0 -j DROP
-A INPUT -s 103.0.0.0/255.0.0.0 -j DROP
-A INPUT -s 104.0.0.0/255.0.0.0 -j DROP
-A INPUT -s 105.0.0.0/255.0.0.0 -j DROP
-A INPUT -s 106.0.0.0/255.0.0.0 -j DROP
-A INPUT -s 127.0.0.0/255.0.0.0 -j DROP
-A INPUT -s 169.254.0.0/255.255.0.0 -j DROP
-A INPUT -s 179.0.0.0/255.0.0.0 -j DROP
-A INPUT -s 185.0.0.0/255.0.0.0 -j DROP
-A INPUT -s 192.0.0.0/255.255.255.0 -j DROP</description> <content:encoded><![CDATA[<p>*mangle<br
/> :PREROUTING ACCEPT [20736884:2763721632]<br
/> :INPUT ACCEPT [20736866:2763715671]<br
/> :FORWARD ACCEPT [0:0]<br
/> :OUTPUT ACCEPT [17305648:26071886184]<br
/> :POSTROUTING ACCEPT [17300520:26071636822]<br
/> -A PREROUTING -p tcp -m tcp &#8211;sport 21 -j TOS &#8211;set-tos 0&#215;08<br
/> -A PREROUTING -p tcp -m tcp &#8211;sport 20 -j TOS &#8211;set-tos 0&#215;08<br
/> -A PREROUTING -p tcp -m tcp &#8211;sport 80 -j TOS &#8211;set-tos 0&#215;08<br
/> -A PREROUTING -p tcp -m tcp &#8211;sport 25 -j TOS &#8211;set-tos 0&#215;10<br
/> -A PREROUTING -p tcp -m tcp &#8211;sport 110 -j TOS &#8211;set-tos 0&#215;10<br
/> -A PREROUTING -p tcp -m tcp &#8211;sport 143 -j TOS &#8211;set-tos 0&#215;10<br
/> -A PREROUTING -p tcp -m tcp &#8211;sport 512:65535 -j TOS &#8211;set-tos 0&#215;00<br
/> -A POSTROUTING -p tcp -m tcp &#8211;dport 21 -j TOS &#8211;set-tos 0&#215;08<br
/> -A POSTROUTING -p tcp -m tcp &#8211;dport 20 -j TOS &#8211;set-tos 0&#215;08<br
/> -A POSTROUTING -p tcp -m tcp &#8211;dport 80 -j TOS &#8211;set-tos 0&#215;08<br
/> -A POSTROUTING -p tcp -m tcp &#8211;dport 25 -j TOS &#8211;set-tos 0&#215;10<br
/> -A POSTROUTING -p tcp -m tcp &#8211;dport 110 -j TOS &#8211;set-tos 0&#215;10<br
/> -A POSTROUTING -p tcp -m tcp &#8211;dport 143 -j TOS &#8211;set-tos 0&#215;10<br
/> -A POSTROUTING -p tcp -m tcp &#8211;dport 512:65535 -j TOS &#8211;set-tos 0&#215;00<br
/> COMMIT</p><p>-A INPUT -s 0.0.0.0/255.0.0.0 -j DROP<br
/> -A INPUT -s 5.0.0.0/255.0.0.0 -j DROP<br
/> -A INPUT -s 23.0.0.0/255.0.0.0 -j DROP<br
/> -A INPUT -s 36.0.0.0/255.0.0.0 -j DROP<br
/> -A INPUT -s 37.0.0.0/255.0.0.0 -j DROP<br
/> -A INPUT -s 39.0.0.0/255.0.0.0 -j DROP<br
/> -A INPUT -s 42.0.0.0/255.0.0.0 -j DROP<br
/> -A INPUT -s 100.0.0.0/255.0.0.0 -j DROP<br
/> -A INPUT -s 102.0.0.0/255.0.0.0 -j DROP<br
/> -A INPUT -s 103.0.0.0/255.0.0.0 -j DROP<br
/> -A INPUT -s 104.0.0.0/255.0.0.0 -j DROP<br
/> -A INPUT -s 105.0.0.0/255.0.0.0 -j DROP<br
/> -A INPUT -s 106.0.0.0/255.0.0.0 -j DROP<br
/> -A INPUT -s 127.0.0.0/255.0.0.0 -j DROP<br
/> -A INPUT -s 169.254.0.0/255.255.0.0 -j DROP<br
/> -A INPUT -s 179.0.0.0/255.0.0.0 -j DROP<br
/> -A INPUT -s 185.0.0.0/255.0.0.0 -j DROP<br
/> -A INPUT -s 192.0.0.0/255.255.255.0 -j DROP</p> ]]></content:encoded> </item> <item><title>By: James</title><link>http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/#comment-48823</link> <dc:creator>James</dc:creator> <pubDate>Tue, 17 Aug 2010 00:16:36 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=5721#comment-48823</guid> <description>I have 601 lines in iptables, is that normal?
I found that after using apf, the iptables -L gave too many drops</description> <content:encoded><![CDATA[<p>I have 601 lines in iptables, is that normal?</p><p>I found that after using apf, the iptables -L gave too many drops</p> ]]></content:encoded> </item> <item><title>By: nixlike</title><link>http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/#comment-48470</link> <dc:creator>nixlike</dc:creator> <pubDate>Thu, 22 Jul 2010 10:29:07 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=5721#comment-48470</guid> <description>Great article, but as for me it&#039;s better to use iptables-{save,restore} commands instead of direct editing of /etc/sysconfig/iptables</description> <content:encoded><![CDATA[<p>Great article, but as for me it&#8217;s better to use iptables-{save,restore} commands instead of direct editing of /etc/sysconfig/iptables</p> ]]></content:encoded> </item> <item><title>By: Vivek Gite</title><link>http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/#comment-47892</link> <dc:creator>Vivek Gite</dc:creator> <pubDate>Thu, 17 Jun 2010 17:52:21 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=5721#comment-47892</guid> <description>Thanks for the heads up!</description> <content:encoded><![CDATA[<p>Thanks for the heads up!</p> ]]></content:encoded> </item> <item><title>By: Lekensteyn</title><link>http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/#comment-47888</link> <dc:creator>Lekensteyn</dc:creator> <pubDate>Thu, 17 Jun 2010 16:52:51 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=5721#comment-47888</guid> <description>You&#039;ve got a typo in your section &#039;Edit /etc/sysctl.conf For DoS and Syn Protection&#039;:
&quot;et.ipv4.conf.all.log_martians = 1&quot;
should be:
&quot;net.ipv4.conf.all.log_martians = 1&quot;</description> <content:encoded><![CDATA[<p>You&#8217;ve got a typo in your section &#8216;Edit /etc/sysctl.conf For DoS and Syn Protection&#8217;:<br
/> &#8220;et.ipv4.conf.all.log_martians = 1&#8243;<br
/> should be:<br
/> &#8220;net.ipv4.conf.all.log_martians = 1&#8243;</p> ]]></content:encoded> </item> <item><title>By: Vivek Gite</title><link>http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/#comment-45510</link> <dc:creator>Vivek Gite</dc:creator> <pubDate>Mon, 11 Jan 2010 04:41:06 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=5721#comment-45510</guid> <description>@pd,
Thanks, I&#039;ve commented out those lines in script, since output policy is set to established.
HTH</description> <content:encoded><![CDATA[<p>@pd,</p><p>Thanks, I&#8217;ve commented out those lines in script, since output policy is set to established.</p><p>HTH</p> ]]></content:encoded> </item> <item><title>By: pd</title><link>http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/#comment-45507</link> <dc:creator>pd</dc:creator> <pubDate>Mon, 11 Jan 2010 01:55:00 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=5721#comment-45507</guid> <description>Yes, I found the problem in below lines, OUTPUT should be with &quot;-o&quot; not &quot;-i&quot;
&lt;pre&gt;# allow incomming ICMP ping pong stuff
$IPT -A INPUT -i ${PUB_IF} -p icmp --icmp-type 8 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
$IPT -A OUTPUT -i ${PUB_IF} -p icmp --icmp-type 0 -m state --state ESTABLISHED,RELATED -j ACCEPT
# Allow port 53 tcp/udp (DNS Server)
$IPT -A INPUT -i ${PUB_IF} -p udp --dport 53 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
$IPT -A OUTPUT -i ${PUB_IF} -p udp --sport 53 -m state --state ESTABLISHED,RELATED -j ACCEPT
$IPT -A INPUT -i ${PUB_IF} -p tcp --destination-port 53 -m state --state NEW,ESTABLISHED,RELATED  -j ACCEPT
$IPT -A OUTPUT -i ${PUB_IF} -p tcp --sport 53 -m state --state ESTABLISHED,RELATED -j ACCEPT&lt;/pre&gt;
Vivek need to update this script.</description> <content:encoded><![CDATA[<p>Yes, I found the problem in below lines, OUTPUT should be with &#8220;-o&#8221; not &#8220;-i&#8221;</p><pre># allow incomming ICMP ping pong stuff
$IPT -A INPUT -i ${PUB_IF} -p icmp --icmp-type 8 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
$IPT -A OUTPUT -i ${PUB_IF} -p icmp --icmp-type 0 -m state --state ESTABLISHED,RELATED -j ACCEPT
# Allow port 53 tcp/udp (DNS Server)
$IPT -A INPUT -i ${PUB_IF} -p udp --dport 53 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
$IPT -A OUTPUT -i ${PUB_IF} -p udp --sport 53 -m state --state ESTABLISHED,RELATED -j ACCEPT
$IPT -A INPUT -i ${PUB_IF} -p tcp --destination-port 53 -m state --state NEW,ESTABLISHED,RELATED  -j ACCEPT
$IPT -A OUTPUT -i ${PUB_IF} -p tcp --sport 53 -m state --state ESTABLISHED,RELATED -j ACCEPT</pre><p>Vivek need to update this script.</p> ]]></content:encoded> </item> <item><title>By: pd</title><link>http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/#comment-45506</link> <dc:creator>pd</dc:creator> <pubDate>Mon, 11 Jan 2010 01:44:03 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=5721#comment-45506</guid> <description>I run this firewall script on centos 5.4 and got these errors
&lt;pre&gt;[root@localhost scripts]# ./iptables.sh
Setting sysctl IPv4 settings...
net.ipv4.ip_forward = 0
net.ipv4.conf.all.send_redirects = 0
net.ipv4.conf.default.send_redirects = 0
net.ipv4.conf.all.accept_source_route = 0
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.all.secure_redirects = 0
net.ipv4.conf.all.log_martians = 1
net.ipv4.conf.default.accept_source_route = 0
net.ipv4.conf.default.accept_redirects = 0
net.ipv4.conf.default.secure_redirects = 0
net.ipv4.icmp_echo_ignore_broadcasts = 1
error: &quot;net.ipv4.icmp_ignore_bogus_error_messages&quot; is an unknown key
net.ipv4.tcp_syncookies = 1
net.ipv4.conf.all.rp_filter = 1
net.ipv4.conf.default.rp_filter = 1
kernel.exec-shield = 1
kernel.randomize_va_space = 1
Starting IPv4 Firewall...
iptables v1.3.5: Can&#039;t use -i with OUTPUT
Try `iptables -h&#039; or &#039;iptables --help&#039; for more information.
iptables v1.3.5: Can&#039;t use -i with OUTPUT
Try `iptables -h&#039; or &#039;iptables --help&#039; for more information.
iptables v1.3.5: Can&#039;t use -i with OUTPUT
Try `iptables -h&#039; or &#039;iptables --help&#039; for more information.&lt;/pre&gt;</description> <content:encoded><![CDATA[<p>I run this firewall script on centos 5.4 and got these errors</p><pre>[root@localhost scripts]# ./iptables.sh
Setting sysctl IPv4 settings...
net.ipv4.ip_forward = 0
net.ipv4.conf.all.send_redirects = 0
net.ipv4.conf.default.send_redirects = 0
net.ipv4.conf.all.accept_source_route = 0
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.all.secure_redirects = 0
net.ipv4.conf.all.log_martians = 1
net.ipv4.conf.default.accept_source_route = 0
net.ipv4.conf.default.accept_redirects = 0
net.ipv4.conf.default.secure_redirects = 0
net.ipv4.icmp_echo_ignore_broadcasts = 1
error: "net.ipv4.icmp_ignore_bogus_error_messages" is an unknown key
net.ipv4.tcp_syncookies = 1
net.ipv4.conf.all.rp_filter = 1
net.ipv4.conf.default.rp_filter = 1
kernel.exec-shield = 1
kernel.randomize_va_space = 1
Starting IPv4 Firewall...
iptables v1.3.5: Can't use -i with OUTPUT
Try `iptables -h' or 'iptables --help' for more information.
iptables v1.3.5: Can't use -i with OUTPUT
Try `iptables -h' or 'iptables --help' for more information.
iptables v1.3.5: Can't use -i with OUTPUT
Try `iptables -h' or 'iptables --help' for more information.</pre>]]></content:encoded> </item> <item><title>By: gorfou</title><link>http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/#comment-44732</link> <dc:creator>gorfou</dc:creator> <pubDate>Tue, 17 Nov 2009 16:48:09 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=5721#comment-44732</guid> <description>Hi,
I am trying to install a custom iptables configuration within a fresh centos/kickstart install.
I have my custom package which installs the file /etc/sysconfig/iptables during kickstart installation.
However, this file is erased by the default one upon first reboot.
Does anyone know what script is responsible for resetting it ?</description> <content:encoded><![CDATA[<p>Hi,<br
/> I am trying to install a custom iptables configuration within a fresh centos/kickstart install.<br
/> I have my custom package which installs the file /etc/sysconfig/iptables during kickstart installation.<br
/> However, this file is erased by the default one upon first reboot.</p><p>Does anyone know what script is responsible for resetting it ?</p> ]]></content:encoded> </item> <item><title>By: yoander (sedlav)</title><link>http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/#comment-44565</link> <dc:creator>yoander (sedlav)</dc:creator> <pubDate>Tue, 10 Nov 2009 14:35:41 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=5721#comment-44565</guid> <description>&lt;a href=&quot;http://easyfwgen.morizot.net/gen/index.php&quot; rel=&quot;nofollow&quot;&gt;Easy Firewall Generator for IPTables&lt;/a&gt; is an iptables script generator, you can play with different options is an excellent tool for newbie.</description> <content:encoded><![CDATA[<p><a
href="http://easyfwgen.morizot.net/gen/index.php" rel="nofollow">Easy Firewall Generator for IPTables</a> is an iptables script generator, you can play with different options is an excellent tool for newbie.</p> ]]></content:encoded> </item> <item><title>By: Vivek Gite</title><link>http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/#comment-44563</link> <dc:creator>Vivek Gite</dc:creator> <pubDate>Tue, 10 Nov 2009 14:11:15 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=5721#comment-44563</guid> <description>@Marcus,
I don&#039;t think so there are any such program under Linux. Almost all network program open privileged or unprivileged ports. You can run netstat program to find out port number and add rule manually.</description> <content:encoded><![CDATA[<p>@Marcus,</p><p>I don&#8217;t think so there are any such program under Linux. Almost all network program open privileged or unprivileged ports. You can run netstat program to find out port number and add rule manually.</p> ]]></content:encoded> </item> <item><title>By: Marcus</title><link>http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/#comment-44562</link> <dc:creator>Marcus</dc:creator> <pubDate>Tue, 10 Nov 2009 13:50:39 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=5721#comment-44562</guid> <description>I&#039;m curious, can you set it up so a certain program is authorized to send/receive data? This is a feature of the Windows Firewall. It makes it easier for programs that don&#039;t publish the ports they work on.</description> <content:encoded><![CDATA[<p>I&#8217;m curious, can you set it up so a certain program is authorized to send/receive data? This is a feature of the Windows Firewall. It makes it easier for programs that don&#8217;t publish the ports they work on.</p> ]]></content:encoded> </item> <item><title>By: Bill Baily</title><link>http://www.cyberciti.biz/faq/rhel-fedorta-linux-iptables-firewall-configuration-tutorial/#comment-44554</link> <dc:creator>Bill Baily</dc:creator> <pubDate>Tue, 10 Nov 2009 12:16:42 +0000</pubDate> <guid
isPermaLink="false">http://www.cyberciti.biz/faq/?p=5721#comment-44554</guid> <description>No mention of *all* the tables then. Mmmm. Perhaps this is just an iptable (rather than an iptables) guide, :-P</description> <content:encoded><![CDATA[<p>No mention of *all* the tables then. Mmmm. Perhaps this is just an iptable (rather than an iptables) guide, :-P</p> ]]></content:encoded> </item> </channel> </rss>
