IPTables: Difference between revisions
Created page with " == Redirect Outgoing Traffic to Local Port == To redirect traffic destined to 1.2.3.4:443 to localhost:8080, use the REDIRECT directive: iptables -t nat -A OUTPUT -p tcp -d..." |
No edit summary |
||
| Line 1: | Line 1: | ||
== Prerouting Chain == | |||
This is the first chain that traffic will go through. It contains the following tables: | |||
# raw | |||
# connection tracking | |||
# mangle | |||
# destination / NAT | |||
=== Drop RFC3330 === | |||
You may wish to drop Special-Use IP addresses defined in RFC 3330. These IPs include internally routed addresses such as 192.168.0.0/16, 10.0.0.0/8, etc., black-hole addresses such as 0.0.0.0, and multicast addresses such as 224.0.0.0/4. There should be no reason for these addresses to be coming in externally and when it does happen, it's probably a spoofed address. | |||
# | |||
# DROP RFC3330 | |||
# | |||
$IPT -t mangle -A PREROUTING -s 0.0.0.0/8 -j DROP -m comment --comment "0.0.0.0/8 source" | |||
$IPT -t mangle -A PREROUTING -d 0.0.0.0/8 -j DROP -m comment --comment "0.0.0.0/8 destination" | |||
$IPT -t mangle -A PREROUTING -s 10.0.0.0/8 -j DROP -m comment --comment "10.0.0.0/8 source" | |||
$IPT -t mangle -A PREROUTING -d 10.0.0.0/8 -j DROP -m comment --comment "10.0.0.0/8 destination" | |||
$IPT -t mangle -A PREROUTING -s 100.64.0.0/10 -j DROP -m comment --comment "100.64.0.0/10 source" | |||
$IPT -t mangle -A PREROUTING -d 100.64.0.0/10 -j DROP -m comment --comment "100.64.0.0/10 destination" | |||
$IPT -t mangle -A PREROUTING -s 127.0.0.0/8 ! -i lo -j DROP -m comment --comment "127.0.0.0/8 source, DROP except on the loopback" | |||
$IPT -t mangle -A PREROUTING -d 127.0.0.0/8 ! -i lo -j DROP -m comment --comment "127.0.0.0/8 destination, DROP except on the loopback" | |||
$IPT -t mangle -A PREROUTING -s 169.254.0.0/16 -j DROP -m comment --comment "169.254.0.0/16 source" | |||
$IPT -t mangle -A PREROUTING -d 169.254.0.0/16 -j DROP -m comment --comment "169.254.0.0/16 destination" | |||
$IPT -t mangle -A PREROUTING -s 172.16.0.0/12 -j DROP -m comment --comment "172.16.0.0/12" | |||
$IPT -t mangle -A PREROUTING -d 172.16.0.0/12 -j DROP -m comment --comment "172.16.0.0/12" | |||
$IPT -t mangle -A PREROUTING -s 192.0.2.0/24 -j DROP -m comment --comment "192.0.2.0/24 source" | |||
$IPT -t mangle -A PREROUTING -d 192.0.2.0/24 -j DROP -m comment --comment "192.0.2.0/24 destination" | |||
$IPT -t mangle -A PREROUTING -s 192.168.0.0/16 -j DROP -m comment --comment "192.168.0.0/16 source" | |||
$IPT -t mangle -A PREROUTING -d 192.168.0.0/16 -j DROP -m comment --comment "192.168.0.0/16 destination" | |||
$IPT -t mangle -A PREROUTING -s 198.18.0.0/15 -j DROP -m comment --comment "198.18.0.0/15 source" | |||
$IPT -t mangle -A PREROUTING -d 198.18.0.0/15 -j DROP -m comment --comment "198.18.0.0/15 destination" | |||
$IPT -t mangle -A PREROUTING -s 198.51.100.0/24 -j DROP -m comment --comment "198.51.100.0/24 source" | |||
$IPT -t mangle -A PREROUTING -d 198.51.100.0/24 -j DROP -m comment --comment "198.51.100.0/24 destination" | |||
$IPT -t mangle -A PREROUTING -s 203.0.113.0/24 -j DROP -m comment --comment "203.0.113.0/24 source" | |||
$IPT -t mangle -A PREROUTING -d 203.0.113.0/24 -j DROP -m comment --comment "203.0.113.0/24 destination" | |||
# Special usue IPs, including 255.255.255.255. | |||
$IPT -t mangle -A PREROUTING -s 240.0.0.0/4 -j DROP -m comment --comment "240.0.0.0/4 source" | |||
$IPT -t mangle -A PREROUTING -d 240.0.0.0/4 -j DROP -m comment --comment "240.0.0.0/4 destination" | |||
# We shouldn't be routing multicast. | |||
$IPT -t mangle -A PREROUTING -s 244.0.0.0/4 -j DROP -m comment --comment "244.0.0.0/4 source" | |||
$IPT -t mangle -A PREROUTING -d 244.0.0.0/4 -j DROP -m comment --comment "244.0.0.0/4 destination" | |||
== Redirect Outgoing Traffic to Local Port == | == Redirect Outgoing Traffic to Local Port == | ||
Revision as of 04:56, 26 June 2013
Prerouting Chain
This is the first chain that traffic will go through. It contains the following tables:
- raw
- connection tracking
- mangle
- destination / NAT
Drop RFC3330
You may wish to drop Special-Use IP addresses defined in RFC 3330. These IPs include internally routed addresses such as 192.168.0.0/16, 10.0.0.0/8, etc., black-hole addresses such as 0.0.0.0, and multicast addresses such as 224.0.0.0/4. There should be no reason for these addresses to be coming in externally and when it does happen, it's probably a spoofed address.
# # DROP RFC3330 # $IPT -t mangle -A PREROUTING -s 0.0.0.0/8 -j DROP -m comment --comment "0.0.0.0/8 source" $IPT -t mangle -A PREROUTING -d 0.0.0.0/8 -j DROP -m comment --comment "0.0.0.0/8 destination" $IPT -t mangle -A PREROUTING -s 10.0.0.0/8 -j DROP -m comment --comment "10.0.0.0/8 source" $IPT -t mangle -A PREROUTING -d 10.0.0.0/8 -j DROP -m comment --comment "10.0.0.0/8 destination" $IPT -t mangle -A PREROUTING -s 100.64.0.0/10 -j DROP -m comment --comment "100.64.0.0/10 source" $IPT -t mangle -A PREROUTING -d 100.64.0.0/10 -j DROP -m comment --comment "100.64.0.0/10 destination" $IPT -t mangle -A PREROUTING -s 127.0.0.0/8 ! -i lo -j DROP -m comment --comment "127.0.0.0/8 source, DROP except on the loopback" $IPT -t mangle -A PREROUTING -d 127.0.0.0/8 ! -i lo -j DROP -m comment --comment "127.0.0.0/8 destination, DROP except on the loopback" $IPT -t mangle -A PREROUTING -s 169.254.0.0/16 -j DROP -m comment --comment "169.254.0.0/16 source" $IPT -t mangle -A PREROUTING -d 169.254.0.0/16 -j DROP -m comment --comment "169.254.0.0/16 destination" $IPT -t mangle -A PREROUTING -s 172.16.0.0/12 -j DROP -m comment --comment "172.16.0.0/12" $IPT -t mangle -A PREROUTING -d 172.16.0.0/12 -j DROP -m comment --comment "172.16.0.0/12" $IPT -t mangle -A PREROUTING -s 192.0.2.0/24 -j DROP -m comment --comment "192.0.2.0/24 source" $IPT -t mangle -A PREROUTING -d 192.0.2.0/24 -j DROP -m comment --comment "192.0.2.0/24 destination" $IPT -t mangle -A PREROUTING -s 192.168.0.0/16 -j DROP -m comment --comment "192.168.0.0/16 source" $IPT -t mangle -A PREROUTING -d 192.168.0.0/16 -j DROP -m comment --comment "192.168.0.0/16 destination" $IPT -t mangle -A PREROUTING -s 198.18.0.0/15 -j DROP -m comment --comment "198.18.0.0/15 source" $IPT -t mangle -A PREROUTING -d 198.18.0.0/15 -j DROP -m comment --comment "198.18.0.0/15 destination" $IPT -t mangle -A PREROUTING -s 198.51.100.0/24 -j DROP -m comment --comment "198.51.100.0/24 source" $IPT -t mangle -A PREROUTING -d 198.51.100.0/24 -j DROP -m comment --comment "198.51.100.0/24 destination" $IPT -t mangle -A PREROUTING -s 203.0.113.0/24 -j DROP -m comment --comment "203.0.113.0/24 source" $IPT -t mangle -A PREROUTING -d 203.0.113.0/24 -j DROP -m comment --comment "203.0.113.0/24 destination" # Special usue IPs, including 255.255.255.255. $IPT -t mangle -A PREROUTING -s 240.0.0.0/4 -j DROP -m comment --comment "240.0.0.0/4 source" $IPT -t mangle -A PREROUTING -d 240.0.0.0/4 -j DROP -m comment --comment "240.0.0.0/4 destination" # We shouldn't be routing multicast. $IPT -t mangle -A PREROUTING -s 244.0.0.0/4 -j DROP -m comment --comment "244.0.0.0/4 source" $IPT -t mangle -A PREROUTING -d 244.0.0.0/4 -j DROP -m comment --comment "244.0.0.0/4 destination"
Redirect Outgoing Traffic to Local Port
To redirect traffic destined to 1.2.3.4:443 to localhost:8080, use the REDIRECT directive:
iptables -t nat -A OUTPUT -p tcp -d 1.2.3.4 --dport 443 -j REDIRECT --to-ports 8080
If you want to redirect traffic to a particular destination rather than 127.0.0.1 (or the primary interface's IP) use DNAT:
iptables -t nat -A OUTPUT -p udp -d 1.2.3.4 --dport 443 -j DNAT --to-destination 9.8.7.6:8080