par Gesp » 08 Août 2003 18:19
C'est dans /etc/rc.d/rc.firewall
<BR>
<BR>Petits extraits
<BR> # This chain will log, then DROPs "Xmas" and Null packets which might
<BR> # indicate a port-scan attempt
<BR> /sbin/iptables -N PSCAN
<BR> /sbin/iptables -A PSCAN -p tcp -m limit --limit 10/minute -j LOG --log-prefix "TCP Scan? "
<BR> /sbin/iptables -A PSCAN -p udp -m limit --limit 10/minute -j LOG --log-prefix "UDP Scan? "
<BR> /sbin/iptables -A PSCAN -p icmp -m limit --limit 10/minute -j LOG --log-prefix "ICMP Scan? "
<BR> /sbin/iptables -A PSCAN -f -m limit --limit 10/minute -j LOG --log-prefix "FRAG Scan? "
<BR> /sbin/iptables -A PSCAN -j DROP
<BR>
<BR> # Disallow packets frequently used by port-scanners, XMas and Null
<BR> /sbin/iptables -A INPUT -p tcp --tcp-flags ALL ALL -j PSCAN
<BR> /sbin/iptables -A FORWARD -p tcp --tcp-flags ALL ALL -j PSCAN
<BR> /sbin/iptables -A INPUT -p tcp --tcp-flags ALL NONE -j PSCAN
<BR> /sbin/iptables -A FORWARD -p tcp --tcp-flags ALL NONE -j PSCAN
<BR>
<BR>
<BR>
<BR>
<BR> # Limit Packets- helps reduce dos/syn attacks
<BR> /sbin/iptables -A INPUT -p tcp -m tcp --tcp-flags SYN,RST,ACK SYN -m limit --limit 10/sec
<BR>