Chapter 43. Securing Your Network
716
you can also use the protocol ID, instead of the protocol name. Refer to the following examples, each
of which have the same effect:
iptables -A INPUT -p icmp --icmp-type any -j ACCEPT
iptables -A INPUT -p 5813 --icmp-type any -j ACCEPT
Service definitions are provided in the
/etc/services
file. For readability, it is recommended that
you use the service names rather than the port numbers.
Important
Secure the
/etc/services
file to prevent unauthorized editing. If this file is editable,
crackers can use it to enable ports on your machine you have otherwise closed. To secure
this file, type the following commands as root:
[root@myServer ~]# chown root.root /etc/services [root@myServer ~]# chmod 0644 /
etc/services [root@myServer ~]# i /etc/services
This prevents the file from being renamed, deleted or having links made to it.
43.9.3.4.1. TCP Protocol
These match options are available for the TCP protocol (
-p tcp
):
•
--dport
— Sets the destination port for the packet.
To configure this option, use a network service name (such as www or smtp); a port number; or a
range of port numbers.
To specify a range of port numbers, separate the two numbers with a colon (
:
). For example:
-p
tcp --dport 3000:3200
. The largest acceptable valid range is
0:65535
.
Use an exclamation point character (
!
) after the
--dport
option to match all packets that
do not
use that network service or port.
To browse the names and aliases of network services and the port numbers they use, view the
/
etc/services
file.
The
--destination-port
match option is synonymous with
--dport
.
•
--sport
— Sets the source port of the packet using the same options as
--dport
. The
--
source-port
match option is synonymous with
--sport
.
•
--syn
— Applies to all TCP packets designed to initiate communication, commonly called
SYN
packets
. Any packets that carry a data payload are not touched.
Use an exclamation point character (
!
) after the
--syn
option to match all non-SYN packets.
•
--tcp-flags <tested flag list> <set flag list>
— Allows TCP packets that have
specific bits (flags) set, to match a rule.
Содержание ENTERPRISE LINUX 5 - VIRTUAL SERVER ADMINISTRATION
Страница 22: ...xxii ...
Страница 28: ......
Страница 36: ...10 ...
Страница 40: ...14 ...
Страница 96: ...70 ...
Страница 116: ...90 ...
Страница 144: ...118 ...
Страница 146: ......
Страница 158: ...132 ...
Страница 165: ...Installing and Removing Packages 139 Figure 11 7 Installing and removing packages simultaneously ...
Страница 166: ...140 ...
Страница 172: ...146 ...
Страница 178: ......
Страница 228: ...202 ...
Страница 264: ...238 ...
Страница 318: ...292 ...
Страница 330: ...304 ...
Страница 388: ...362 ...
Страница 428: ...402 ...
Страница 452: ......
Страница 458: ...432 ...
Страница 476: ...450 ...
Страница 478: ...452 ...
Страница 494: ...468 ...
Страница 498: ...472 ...
Страница 530: ...504 ...
Страница 536: ...510 ...
Страница 544: ...Chapter 36 Log Files 518 Figure 36 7 Log file contents after five seconds ...
Страница 546: ......
Страница 550: ...524 ...
Страница 576: ......
Страница 584: ...558 ...
Страница 608: ......
Страница 776: ...750 ...
Страница 796: ...770 ...
Страница 800: ...774 ...
Страница 804: ......
Страница 806: ...780 ...
Страница 808: ...782 ...
Страница 816: ...790 ...
Страница 820: ...794 ...
Страница 822: ...796 ...
Страница 830: ...804 ...
Страница 836: ...810 ...
Страница 844: ...818 ...
Страница 848: ...822 ...