Heu ....premier souci : mes règles iptables (qui fonctionnent très bien avec l'ancien noyau)
[root@bob ~]#
/etc/fw_redfox
iptables v1.3.5: can't initialize iptables table `nat': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.3.5: can't initialize iptables table `nat': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.3.5: can't initialize iptables table `nat': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.3.5: can't initialize iptables table `nat': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
iptables v1.3.5: can't initialize iptables table `nat': Table does not exist (do you need to insmod?)
Perhaps iptables or your kernel needs to be upgraded.
iptables: Unknown error 4294967295
iptables: Unknown error 4294967295
[root@bob ~]#
[root@bob ~]#
cat /etc/fw_redfox
#!/bin/bash
iptables -F
iptables -X
iptables -t filter -P INPUT DROP
iptables -t filter -P OUTPUT DROP
iptables -t filter -P FORWARD DROP
iptables -t nat -F
iptables -t nat -X
iptables -t nat -P PREROUTING ACCEPT
iptables -t nat -P POSTROUTING ACCEPT
iptables -t nat -P OUTPUT ACCEPT
iptables -t mangle -F
iptables -t mangle -X
iptables -t mangle -P PREROUTING ACCEPT
iptables -t mangle -P POSTROUTING ACCEPT
iptables -t mangle -P INPUT ACCEPT
iptables -t mangle -P OUTPUT ACCEPT
iptables -t mangle -P FORWARD ACCEPT
# interface lo
iptables -A INPUT -i lo -j ACCEPT
iptables -A OUTPUT -o lo -j ACCEPT
# interface eth0:192.168.1.2
iptables -A INPUT -i eth0 -d 192.168.1.2 -s 0.0.0.0/0 -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A OUTPUT -o eth0 -s 192.168.1.2 -d 0.0.0.0/0 -m state --state ! INVALID -j ACCEPT
# client ssh 192.168.1.3
iptables -A INPUT -i eth0 -d 192.168.1.2 -s 192.168.1.2 -p tcp --dport 22 -j ACCEPT
# client ssh xxxxx
iptables -A INPUT -i eth0 -d 192.168.1.2 -s xx.xxx.xxx.xxx -p tcp --dport 22 -j ACCEPT
menuconfig : je n'ai rien modifié !
alors dois-je recompiler en rajoutant une option ?
Merci.
:-))