1 |
nightmorph 09/09/18 08:36:43 |
2 |
|
3 |
Modified: home-router-howto.xml |
4 |
Log: |
5 |
update home router guide for the new iptables syntax, patch from bug 285416 |
6 |
|
7 |
Revision Changes Path |
8 |
1.63 xml/htdocs/doc/en/home-router-howto.xml |
9 |
|
10 |
file : http://sources.gentoo.org/viewcvs.py/gentoo/xml/htdocs/doc/en/home-router-howto.xml?rev=1.63&view=markup |
11 |
plain: http://sources.gentoo.org/viewcvs.py/gentoo/xml/htdocs/doc/en/home-router-howto.xml?rev=1.63&content-type=text/plain |
12 |
diff : http://sources.gentoo.org/viewcvs.py/gentoo/xml/htdocs/doc/en/home-router-howto.xml?r1=1.62&r2=1.63 |
13 |
|
14 |
Index: home-router-howto.xml |
15 |
=================================================================== |
16 |
RCS file: /var/cvsroot/gentoo/xml/htdocs/doc/en/home-router-howto.xml,v |
17 |
retrieving revision 1.62 |
18 |
retrieving revision 1.63 |
19 |
diff -u -r1.62 -r1.63 |
20 |
--- home-router-howto.xml 19 Aug 2008 14:15:59 -0000 1.62 |
21 |
+++ home-router-howto.xml 18 Sep 2009 08:36:43 -0000 1.63 |
22 |
@@ -1,6 +1,6 @@ |
23 |
<?xml version='1.0' encoding='UTF-8'?> |
24 |
<!DOCTYPE guide SYSTEM "/dtd/guide.dtd"> |
25 |
-<!-- $Header: /var/cvsroot/gentoo/xml/htdocs/doc/en/home-router-howto.xml,v 1.62 2008/08/19 14:15:59 vapier Exp $ --> |
26 |
+<!-- $Header: /var/cvsroot/gentoo/xml/htdocs/doc/en/home-router-howto.xml,v 1.63 2009/09/18 08:36:43 nightmorph Exp $ --> |
27 |
|
28 |
<guide link="/doc/en/home-router-howto.xml" lang="en"> |
29 |
<title>Home Router Guide</title> |
30 |
@@ -17,8 +17,8 @@ |
31 |
<!-- The content of this document is released into the public domain --> |
32 |
<license/> |
33 |
|
34 |
-<version>1.39</version> |
35 |
-<date>2008-08-19</date> |
36 |
+<version>1.40</version> |
37 |
+<date>2009-09-18</date> |
38 |
|
39 |
<chapter> |
40 |
<title>Introduction</title> |
41 |
@@ -440,15 +440,15 @@ |
42 |
<comment>Then we lock our services so they only work from the LAN</comment> |
43 |
# <i>iptables -I INPUT 1 -i ${LAN} -j ACCEPT</i> |
44 |
# <i>iptables -I INPUT 1 -i lo -j ACCEPT</i> |
45 |
-# <i>iptables -A INPUT -p UDP --dport bootps -i ! ${LAN} -j REJECT</i> |
46 |
-# <i>iptables -A INPUT -p UDP --dport domain -i ! ${LAN} -j REJECT</i> |
47 |
+# <i>iptables -A INPUT -p UDP --dport bootps ! -i ${LAN} -j REJECT</i> |
48 |
+# <i>iptables -A INPUT -p UDP --dport domain ! -i ${LAN} -j REJECT</i> |
49 |
|
50 |
<comment>(Optional) Allow access to our ssh server from the WAN</comment> |
51 |
# <i>iptables -A INPUT -p TCP --dport ssh -i ${WAN} -j ACCEPT</i> |
52 |
|
53 |
<comment>Drop TCP / UDP packets to privileged ports</comment> |
54 |
-# <i>iptables -A INPUT -p TCP -i ! ${LAN} -d 0/0 --dport 0:1023 -j DROP</i> |
55 |
-# <i>iptables -A INPUT -p UDP -i ! ${LAN} -d 0/0 --dport 0:1023 -j DROP</i> |
56 |
+# <i>iptables -A INPUT -p TCP ! -i ${LAN} -d 0/0 --dport 0:1023 -j DROP</i> |
57 |
+# <i>iptables -A INPUT -p UDP ! -i ${LAN} -d 0/0 --dport 0:1023 -j DROP</i> |
58 |
|
59 |
<comment>Finally we add the rules for NAT</comment> |
60 |
# <i>iptables -I FORWARD -i ${LAN} -d 192.168.0.0/255.255.0.0 -j DROP</i> |
61 |
@@ -814,7 +814,7 @@ |
62 |
# <i>emerge netqmail</i> |
63 |
<comment>make sure the output of `hostname` is correct</comment> |
64 |
# <i>emerge --config netqmail</i> |
65 |
-# <i>iptables -I INPUT -p tcp --dport smtp -i ! ${LAN} -j REJECT</i> |
66 |
+# <i>iptables -I INPUT -p tcp --dport smtp ! -i ${LAN} -j REJECT</i> |
67 |
# <i>ln -s /var/qmail/supervise/qmail-send /service/qmail-send</i> |
68 |
# <i>ln -s /var/qmail/supervise/qmail-smtpd /service/qmail-smtpd</i> |
69 |
# <i>cd /etc/tcprules.d</i> |