par tomtom » 13 Mai 2003 15:38
Demonstration :
<BR>
<BR>(le message n'est pas le même suivant les noyaux, les règles, etc...)
<BR>
<BR>tekila:~# ping 172.16.2.2
<BR>PING 172.16.2.2 (172.16.2.2): 56 data bytes
<BR>64 bytes from 172.16.2.2: icmp_seq=0 ttl=128 time=2.5 ms
<BR>64 bytes from 172.16.2.2: icmp_seq=1 ttl=128 time=1.1 ms
<BR>
<BR>--- 172.16.2.2 ping statistics ---
<BR>2 packets transmitted, 2 packets received, 0% packet loss
<BR>round-trip min/avg/max = 1.1/1.8/2.5 ms
<BR>
<BR>tekila:~# iptables -I OUTPUT -p icmp -j DROP
<BR>
<BR>tekila:~# ping 172.16.2.2
<BR>PING 172.16.2.2 (172.16.2.2): 56 data bytes
<BR>ping: sendto: Operation not permitted
<BR>ping: wrote 172.16.2.2 64 chars, ret=-1
<BR>ping: sendto: Operation not permitted
<BR>ping: wrote 172.16.2.2 64 chars, ret=-1
<BR>
<BR>--- 172.16.2.2 ping statistics ---
<BR>2 packets transmitted, 0 packets received, 100% packet loss
<BR>
<BR>tekila:~# iptables -D OUTPUT -p icmp -j DROP
<BR>tekila:~# ping 172.16.2.2
<BR>PING 172.16.2.2 (172.16.2.2): 56 data bytes
<BR>64 bytes from 172.16.2.2: icmp_seq=0 ttl=128 time=2.5 ms
<BR>64 bytes from 172.16.2.2: icmp_seq=1 ttl=128 time=1.3 ms
<BR>
<BR>--- 172.16.2.2 ping statistics ---
<BR>2 packets transmitted, 2 packets received, 0% packet loss
<BR>round-trip min/avg/max = 1.3/1.9/2.5 ms
<BR>
<BR>
<BR>
<BR>Et voila <IMG SRC="images/smiles/icon_smile.gif">
<BR>
<BR>C'est pas plus compliqué <IMG SRC="images/smiles/icon_razz.gif">
<BR>
<BR>Tom
One hundred thousand lemmings can't be wrong...