Shorewall and tcdump

Forum sur la sécurité des réseaux, la configuration des firewalls, la mise en place de protections contre les attaques, de DMZ, de systèmes anti-intrusion ...

Modérateur: modos Ixus

Shorewall and tcdump

Messagepar gbe54 » 27 Oct 2007 12:45

Hi,

A few time ago I tried to record a UDP multicast with a software of mine. This software won't work until I opened the right port with shorewall.
But tcpdump and ethereal managed to get the broadcast despite the port being blocked by the firewall.

I can't understand why. Any Idea ?

Thanks in advance.

GBE
gbe54
Matelot
Matelot
 
Messages: 1
Inscrit le: 27 Oct 2007 12:41

Messagepar jdh » 27 Oct 2007 13:07

Shorewall generate netfilter instructions from its configuration files. The result is like ANY script directly written with iptables instructions.

I imagine (and I can see) software like tcpdump, nmap, ethereal acting at an upper level are running in the context set by Shorewall. And if a rule is designed for dropping/rejecting network flows in Shorewall, it's NOT possible to listen these flows with these tools.

Netfilter is deeply inside the kernel and its ip-stack. So, tools using ressources of the stack, even in promiscious mode, must follow the rules designed by settings of netfilter. (Better "receives the network packets allowed by netfilter rules").

IMHO.
Avatar de l’utilisateur
jdh
Amiral
Amiral
 
Messages: 4741
Inscrit le: 29 Déc 2002 01:00
Localisation: Nantes

Messagepar tomtom » 28 Oct 2007 10:49

Hello,

Please use french language in this forum !

Sorry if you don't speak french, we do not allow english questions here as our forums are to be red by people not speaking english.


t.
One hundred thousand lemmings can't be wrong...
Avatar de l’utilisateur
tomtom
Amiral
Amiral
 
Messages: 6035
Inscrit le: 26 Avr 2002 00:00
Localisation: Paris


Retour vers Sécurité et réseaux

Qui est en ligne ?

Utilisateur(s) parcourant actuellement ce forum : Aucun utilisateur inscrit et 0 invité(s)

cron