Hello,
I have a Lenny Host running VirtualBox 3.0.2 and a guest running Lenny too.
At the host, I have this network interfaces:
ip link
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 16436 qdisc noqueue state UNKNOWN
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 100
link/ether 00:1c:c0:05:04:0e brd ff:ff:ff:ff:ff:ff
3: vboxnet0: <BROADCAST,MULTICAST> mtu 1500 qdisc noop state DOWN qlen 1000
link/ether 0a:00:27:00:00:00 brd ff:ff:ff:ff:ff:ff
I want to configure an iptables firewall on the host to protect the host server; and other firewall in the guest to protect the guest (if that is the correct way of protecting the guest)
When I put something like this on the host:
iptables -P FORWARD DROP
iptables -P INPUT DROP
iptables -P OUTPUT ACCEPT
iptables -A INPUT -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
echo "Acceso SSH"
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
nothing is bloqued at the host nor on the guest.
How should I configure iptables on the host to protect it?
Hoy should I configure iptables on the guest to protect it too?
Thanks in advance and sorry for my bad english.
Pablo.
[Solved] Configure iptables to block traffic on Host
-
baf
- Volunteer
- Posts: 829
- Joined: 27. Sep 2008, 06:18
- Primary OS: Mac OS X Leopard
- VBox Version: VirtualBox+Oracle ExtPack
- Guest OSses: linux,xp,win7
- Location: Luleå or Skellefteå, Sweden
Re: Configure iptables to block traffic on Host
What is the output of iptables-save after those commands?
Some say: "You learn as long as you live".
My way: "You live as long as you learn".
My way: "You live as long as you learn".
-
parmando
- Posts: 5
- Joined: 23. Jul 2009, 20:11
- Primary OS: Debian Lenny
- VBox Version: VirtualBox+Oracle ExtPack
- Guest OSses: Debian - Windows
Re: Configure iptables to block traffic on Host
Here is the output:
# Generated by iptables-save v1.4.2 on Thu Jul 23 16:27:53 2009
*mangle
:PREROUTING ACCEPT [14794:1113662]
:INPUT ACCEPT [8947:580615]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [8331:5432967]
:POSTROUTING ACCEPT [8331:5432967]
COMMIT
# Completed on Thu Jul 23 16:27:53 2009
# Generated by iptables-save v1.4.2 on Thu Jul 23 16:27:53 2009
*nat
:PREROUTING ACCEPT [9082:714889]
:POSTROUTING ACCEPT [67:5420]
:OUTPUT ACCEPT [67:5420]
COMMIT
# Completed on Thu Jul 23 16:27:53 2009
# Generated by iptables-save v1.4.2 on Thu Jul 23 16:27:53 2009
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [5:716]
-A INPUT -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
COMMIT
# Completed on Thu Jul 23 16:27:53 2009
# Generated by iptables-save v1.4.2 on Thu Jul 23 16:27:53 2009
*mangle
:PREROUTING ACCEPT [14794:1113662]
:INPUT ACCEPT [8947:580615]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [8331:5432967]
:POSTROUTING ACCEPT [8331:5432967]
COMMIT
# Completed on Thu Jul 23 16:27:53 2009
# Generated by iptables-save v1.4.2 on Thu Jul 23 16:27:53 2009
*nat
:PREROUTING ACCEPT [9082:714889]
:POSTROUTING ACCEPT [67:5420]
:OUTPUT ACCEPT [67:5420]
COMMIT
# Completed on Thu Jul 23 16:27:53 2009
# Generated by iptables-save v1.4.2 on Thu Jul 23 16:27:53 2009
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [5:716]
-A INPUT -m state --state NEW,RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p tcp -m tcp --dport 22 -j ACCEPT
COMMIT
# Completed on Thu Jul 23 16:27:53 2009
-
baf
- Volunteer
- Posts: 829
- Joined: 27. Sep 2008, 06:18
- Primary OS: Mac OS X Leopard
- VBox Version: VirtualBox+Oracle ExtPack
- Guest OSses: linux,xp,win7
- Location: Luleå or Skellefteå, Sweden
Re: Configure iptables to block traffic on Host
This rule in the filter chain:
Means accept all new and previously established connections. So nothing should be dropped.
Try
instead.
Code: Select all
-A INPUT -m state --state NEW,RELATED,ESTABLISHED -j ACCEPTTry
Code: Select all
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPTSome say: "You learn as long as you live".
My way: "You live as long as you learn".
My way: "You live as long as you learn".
-
parmando
- Posts: 5
- Joined: 23. Jul 2009, 20:11
- Primary OS: Debian Lenny
- VBox Version: VirtualBox+Oracle ExtPack
- Guest OSses: Debian - Windows
Re: Configure iptables to block traffic on Host
Thank you very much. That was the problem. I have to see with more care next time:(.