- Mastering Linux Security and Hardening
- Donald A. Tevault
- 376字
- 2021-07-02 19:19:27
An overview of iptables
A common misconception is that iptables is the name of the Linux firewall. In reality, the name of the Linux firewall is netfilter and every Linux distro has it built-in. What we know as iptables is just one of several command-line utilities that we can use to manage netfilter. It was originally introduced as a feature of Linux kernel, version 2.6, so it's been around for a long time. With iptables, you do have a few advantages:
- It's been around long enough that most Linux admins already know how to use it
- It's easy to use iptables commands in shell scripts to create your own custom firewall configuration
- It has great flexibility, in that you can use it to set up a simple port filter, a router, or a virtual private network
- It comes preinstalled on pretty much every Linux distro, although most distros don't come with it preconfigured
- It's very well documented, with free of charge, book-length tutorials available on the internet
But, as you might know, there are also a few disadvantages:
- IPv4 and IPv6 require their own special implementation of iptables. So, if your organization still needs to run IPv4 while in the process of migrating to IPv6, you'll have to configure two firewalls on each server, and run a separate daemon for each (one for IPv4, the other for IPv6).
- If you need to do Mac bridging that requires ebtables, which is the third component of iptables, with its own unique syntax.
- arptables, the fourth component of iptables, also requires its own daemon and syntax.
- Whenever you add a rule to a running iptables firewall, the entire iptables ruleset has to be reloaded, which can have a huge impact on performance.
Until recently, iptables was the default firewall manager on every Linux distro. It still is on most distros, but Red Hat Enterprise Linux 7 and all of its offspring now use a newer technology called firewalld. Ubuntu comes with Uncomplicated Firewall (ufw), an easy-to-use frontend for iptables. An even newer technology that we'll explore at the end of the chapter is nftables.
For the purposes of this chapter, we'll only look at the IPv4 component of iptables. (The syntax for the IPv6 component would be very similar.)
- CTF實(shí)戰(zhàn):技術(shù)、解題與進(jìn)階
- Securing Blockchain Networks like Ethereum and Hyperledger Fabric
- Kali Linux CTF Blueprints
- 大型互聯(lián)網(wǎng)企業(yè)安全架構(gòu)
- 網(wǎng)絡(luò)空間安全:管理者讀物
- 數(shù)字安全藍(lán)皮書:本質(zhì)屬性與重要特征
- Computer Forensics with FTK
- ARM匯編與逆向工程:藍(lán)狐卷·基礎(chǔ)知識
- 網(wǎng)絡(luò)安全設(shè)計(jì)、配置與管理大全
- 網(wǎng)絡(luò)用戶行為的安全可信分析與控制
- Bug Bounty Hunting Essentials
- Kali Linux高級滲透測試(原書第4版)
- 數(shù)字政府網(wǎng)絡(luò)安全合規(guī)性建設(shè)指南:密碼應(yīng)用與數(shù)據(jù)安全
- 黑客攻防從入門到精通:命令版
- Android Application Security Essentials