|
I purpose of this article
This article mainly discusses various new features and usage methods of iptables in Linux 2.4 kernel, how to effectively use these new features to Set firewall rules for enterprises, and illustrates the application of new features in enterprises.
2. Operating Environment
Redhat Linux 7.1 comes with a modular kernel that connects to the Internet through a leased line. The firewall of two NICs has an intranet segment of 10.0.0.0/255.255.255.0 and the interface address of the firewall's external Nic is 1.2.3.4.
Differences between iptables and ipchains
1. the built-in rules are redefined to simplify the management of built-in INPUT, OUTPUT, and FORWARD rules in the new iptables in Linux kernel, any package is only applied to any of the three rules, hit by the INPUT rule, or hit by the FORWARD rule or OUTPUT rule, unlike in ipchains, if any package passes through this firewall, it always hits three rules at the same time.
To illustrate this change, see. ()
Incoming/Outgoing
--> [Routing] ---> | FORWARD | ------->
[Demo-] _____/^
|
V ____
___/
/Linux Firewall | OUTPUT |
| INPUT | ____/
___/^
|
----> Local Process ----
A. First, when a packet comes in, that is, entering the firewall from the ethernet card, the kernel first sets the packet target according to the route voting.
B. If the target host is a local host, the local host directly enters the INPUT chain and waits for the packets to be received and ends.
C. otherwise, if the packet from the ethernet card is not the local machine, check whether the kernel allows forwarding packets (use echo 1>/proc/sys/net/ipv4/ip_forward to enable the forwarding function) if Forwarding is not permitted, the packets are dropped. If Forwarding is permitted, the packets are sent to the local machine and the packets are stopped. In this case, no INPUT or OUTPUT chain is passed, because the route destination is not the local machine and is only applied by forwarding rules.
D. At last, the linux firewall host can generate packages, which are only linked out of the OUTPUT chain.
Note: echo 1> the difference between/proc/sys/net/ipv4/ip_forward and FORWARD chains
The former indicates whether to enable the forwarding function of the kernel. The latter means that only when the kernel enables the forwarding function of the forwarding chain rule can a package be sent to the forwarding chain to check the rules one by one. If a firewall does not enable the IP forwarding function of the former, the Network on both sides of the root firewall is completely isolated. If one end is connected to the internet, you can only ask the internet via proxy, it is impossible to prevent the problem through IP address disguise.
In this way, any package can only apply one rule in INPUT/OUTPUT/FORWARD. This huge improvement also simplifies firewall rule management.
2. iptables is stateful (stateful ).
Stateful means that if a packet is a response to the packet originally sent from the firewall, the system automatically allows the reply packet to enter and return it to the requester without checking any rules, in this way, we do not need to set many rule definitions to implement the desired functions. Using this stateful capability in the new kernel is strongly recommended. How can we enable and use this feature? See. ()
Assume that a company has a typical internet connection solution as shown in the following figure:
_______
10.0.0.2 |
| PC | (10.0.0.1) eth1 | eth0 (1.2.3.4)
B | ___ | _ _______________ | firewall | --------- Internet
(LAN: 10.0.0.0/24) | A |
| _______ |
You can use the following rule set to use the stateful capabilities of iptables and enable the IP camouflage function.
1 modprobe ip_tables
2 echo 1>/proc/sys/net/ipv4/ip_forward
3 iptables-F INPUT
4 iptables-F FORWARD
5 iptables-f postrouting-t nat
6 iptables-P FORWARD DROP
7 iptables-a forward-s 10.0.0.0/24-j ACCEPT
8 iptables-a forward-I eth0-m state -- state ESTABLISHED, RELATED-j
ACCEPT
9 iptables-t nat-a postrouting-o eth0-s 10.0.0.0/24-j MASQUERADE
10 iptables-a input-p tcp-I eth0 -- syn -- dport 80-j ACCEPT
11 iptables-a input-p tcp-I eth0 -- syn-j DROP
Note:
1. When the redhat modular kernel is used, after the ip_tables module is loaded, future commands will load the required modules as needed. In addition, if you have installed the ipchains or ipfwadm module, you cannot mount the iptables module any more. You can run the rmmod command to remove it and then mount the iptables module. In redhat, you can use ntsysv to remove ipchains and iptables to mark the restart and then run the preceding command. Or put it in/etc/rc. d/rc. local to run automatically.
2. Enable the IP forwarding function in the second line.
3. Clear the INPUT, FORWARD, and POSTROUTING key rules in the third or fourth row.
4. in Row 6, the default forwarding policy is set to DROP. When a packet is forwarded to the application but cannot be applied to any forwarding rule, the default rule is applied.
5. Row 7 forwards packets from machines in this segment to any place.
6. Row 8 utilizes stateful capabilities, as long as it is a response to the request packet that was previously sent out of the firewall's external interface. ESTABLISHED refers to a TCP connection, and RELATED refers to an active FTP or ICMP ping request. When the reply packet arrives, it actually checks whether the file/proc/net/ip_conntrack is in it, if any chain is not checked in the table, the package can pass.
7. In the ninth line, the IP spoofing capability is enabled. The packet sent out of eth0 is overwritten and then disguised as the source address SNAT. Here, we should note that-o eth0, instead of-I eth0. In iptables, the packet from an interface is-o, and the incoming packet is-I
8. Row 10 indicates that if this firewall is also a WEB server, new external requests and packets with the target port 80 can enter
9. Row 11th rejects incoming TCP connection request packets that are not requested by the target port 80.
Note: Relationship between NAT and FORWARD chains
A. regardless of any NAT, the Source and Destination addresses displayed in the packet filtering rule are the real source and destination addresses, even though the packet address is overwritten when the IP disguise (DNAT) is executed, you can use
/Proc/net/ip_conntrack.
B. if we do not use the stateful capabilities of iptables, as in the above case, if we allow machines in the network segment 10.0.0.0/24 to disguise IP addresses, we have to add A forwarding rule iptables-a forward-d 10.0.0.0/24-j ACCEPT. Otherwise, the response to the disguised package will not be sent to the internal machine through the forwarding chain, because the reply packet must pass the forwarding link.
Note: How can I prove that only one rule chain has been applied?
In the previous ipchains, a package must pass the input, forward, and output chain before it can be sent from the firewall to the internet. Now, using iptables, only one chain is applied. You can add the following rules to test.
Iptables-a input-s 10.0.0.2/24-j DROP
In iptables, the above line only indicates that any machine in this segment is rejected when the target is a firewall, but does not affect NAT and forwarding packets. This is impossible in the previous ipchains.
3. Easy implementation of transparent proxy and port forwarding
A. port forwarding
In linux 2.4, NAT is divided into SNAT (source NAT) and DNAT (destination NAT ). We can use SNAT and DNAT to easily implement transparent proxy, redirection, and port forwarding functions.
Assume that the network structure of a company is as follows:
10.0.0.2 |
| PC | (10.0.0.1) eth1 | eth0 (1.2.3.4), eth0: 0 (1.2.3.5)
B | ___ | _ _______________ | firewall | --------- Internet
(LAN: | 10.0.0.0/24) | A |
| _______ |
|
_____
|
| C | Linux POP3 server
| _____ | IP: 10.0.0.3 gw: 10.0.0.1
When a packet is routed, the source address is rewritten before it is forwarded, and the source address is changed to 1.2.3.5 (the alias IP address on the firewall)
Iptables-t nat-a postrouting-s 10.0.0.3-o eth0-j SNAT -- to 1.2.3.5
IP spoofing is a special case of SNAT. When camouflage is required, requests from the source address are not required. In the above example, there is a Linux POP3 server in the LAN with the IP address 10.0.0.3, the gateway is 10.0.0.1, and an IP alias 1.2.3.5 is bound to the external Nic of the firewall, as the source IP address of the POP3 server. For external users (employees are on a business trip), this IP address 1.2.3.5 is the IP address of the POP3 server. When requesting this IP address, we use DNAT to send it to 10.0.0.3 to implement port forwarding.
Iptables-t nat-a prerouting-I eth0-d 1.2.3.5-j DNAT -- to 10.0.0.3
Then, these two rows of rules can implement port forwarding.
B. Transparent proxy (redirection)
The most common use of transparent proxy is the combination of open source proxy software Squid, so that users in the LAN do not need to set any browser proxy
The proxy is used transparently to access the Internet. If our Squid HTTP port runs on port 3333, use the following rules:
Iptables-t nat-a prerouting-I eth1-p tcp-s 10.0.0.0/24 -- dport 80-j
DNAT -- to 10.0.0.1: 3333
You must also set Squid. conf in squid 2.3 or 2.4 as follows:
Http_port 3333
Httpd_accel_host virtual
Httpd_accel_port 80
Httpd_accel_with_proxy on
Httpd_accel_uses_host_header on
In this way, even if no proxy is set, users in the LAN also use the Squid proxy to access the Internet.
4. FAQs
A. How can I save the running firewall rules for the iptables service in ntsysv of redhat?
Use iptables-save and iptables-restore to save the file as/etc/sysconfig/iptables, and then use ntsysv to start iptables service.
B. Can I use ipchains and iptables at the same time?
No. Before using iptalbes, you must stop ipchains and ipchains-related modules in any memory. Use/sbin/lsmod to check all ipchains and delete them one by one with/sbin/rmmod, finally, run the iptables rule. |