par PaTou31 » 05 Jan 2004 13:13
<!-- BBCode Quote Start --><TABLE BORDER=0 ALIGN=CENTER WIDTH=85%><TR><TD><font size=-2>En réponse à:</font><HR></TD></TR><TR><TD><FONT SIZE=-2><BLOCKQUOTE>
<BR>Le 2004-01-05 11:37, PaTou31 a écrit:
<BR>Hello
<BR>
<BR>Je suis aussi en train d'essayer de mettre ca en place, mais je suis pas trop sur de savoir ou le placer exactement, j'ai donc tenter de placer comme ca, est ce que c'est ok?
<BR>
<BR>En voyant ce qui est au dessus dans Allow ICMP echo-request j'ai des doutes.
<BR>
<BR>Mon ipcop est 1.4.0.a.2
<BR>
<BR> # Allow ICMP echo-request (ping), all other essential ICMP will be either
<BR> # ESTABLISHED or RELATED, and the rest caught by the default DENY policy
<BR> /sbin/iptables -A INPUT -p icmp --icmp-type 8 -j ACCEPT
<BR>
<BR> # Accept everything connected
<BR> /sbin/iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
<BR> /sbin/iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
<BR>
<BR> # localhost and ethernet.
<BR> /sbin/iptables -A INPUT -i lo -j ACCEPT
<BR> /sbin/iptables -A INPUT -p icmp --icmp-type 0 -j DROP
<BR> /sbin/iptables -A INPUT -p icmp --icmp-type 5 -j DROP
<BR> /sbin/iptables -A INPUT -p icmp --icmp-type 8 -j DROP
<BR> /sbin/iptables -A INPUT -s 127.0.0.0/8 -j DROP # Loopback not on lo
<BR> /sbin/iptables -A INPUT -d 127.0.0.0/8 -j DROP
<BR> /sbin/iptables -A INPUT -i $GREEN_DEV -m state --state NEW -j ACCEPT
<BR> /sbin/iptables -A FORWARD -i $GREEN_DEV -m state --state NEW -j ACCEPT
<BR>
<BR></BLOCKQUOTE></FONT></TD></TR><TR><TD><HR></TD></TR></TABLE><!-- BBCode Quote End -->
<BR>
<BR>Faut que je change ici?
<BR>
<BR> # Allow ICMP echo-request (ping), all other essential ICMP will be either
<BR> # ESTABLISHED or RELATED, and the rest caught by the default DENY policy
<BR> /sbin/iptables -I INPUT -p icmp --icmp-type 8 -j ACCEPT
<BR>
<BR>Ou ici ?
<BR>
<BR> # localhost and ethernet.
<BR> /sbin/iptables -I INPUT -i lo -j ACCEPT
<BR> /sbin/iptables -I INPUT -p icmp --icmp-type 0 -j DROP
<BR> /sbin/iptables -I INPUT -p icmp --icmp-type 5 -j DROP
<BR> /sbin/iptables -I INPUT -p icmp --icmp-type 8 -j DROP
<BR> /sbin/iptables -A INPUT -s 127.0.0.0/8 -j DROP # Loopback not on lo
<BR> /sbin/iptables -A INPUT -d 127.0.0.0/8 -j DROP
<BR> /sbin/iptables -A INPUT -i $GREEN_DEV -m state --state NEW -j ACCEPT
<BR> /sbin/iptables -A FORWARD -i $GREEN_DEV -m state --state NEW -j ACCEPT
<BR>
<BR>Desole, mais je suis pas vraiment bon <IMG SRC="images/smiles/icon_frown.gif">
<BR>
<BR>_________________
<BR>-=] PaTou [=-<BR><BR><font size=-2></font>
-=] PaTou [=-