OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [suse-security] Unwanted routing between subnets

From: Holger Schletz (h.schletzdokom.net)
Date: Wed Sep 10 2003 - 04:03:37 CDT


Thanks, that helped.

I tried this before, but only on the INPUT chain. Too busy to see the obvious
:-]

However, adding a ruleset for the INPUT chain is still necessary to protect
the interfaces on the router itself, as these are not handled by the FORWARD
chain.

Bye,
Holger

Am Dienstag, 9. September 2003 08:40 schrieb BLeonhardtanalytek.de:
> Hi,
>
> a rule like
>
> iptables -A FORWARD -i eth0 -s 192.168.0.0/16 -d 172.16.0.0/16 -j DROP
> iptables -A FORWARD -i eth0 -s 172.16.0.0/16 -d 192.168.0.0/16 -j DROP
>
> wouldn't work ?
>
> Mit freundlichen Grüßen / Best regards
> Bruno Leonhardt
>
> LPI Level 1 Certified
> Watchguard Certified System Professional
> CLP Domino R5 Systemadministrator

--
Check the headers for your unsubscription address
For additional commands, e-mail: suse-security-helpsuse.com
Security-related bug reports go to securitysuse.de, not here