h.stroph <(E-Mail Removed)> wrote:
> Only an incompetent fool of an administrator would want such an unfiltered
> traffic.
This particular computer is a public access machine and the traffic is
already being filtered by a remote hardware based firewall device and
intermediate routing devices. The specific filtering on port 7500 is
being done locally on the machine in supplement to the external
firewalling due to a limitation of the external hardware based firewall,
which is not able to handle a lengthy access list chain against the
forwarded 7500 service port. The computer is providing public access web
services, news feeds, email, internet relay chat, game services and internal
networking services, such as internal client access, and network file services
on several port numbers.
I don't want a change to the iptables list to affect those services. All I
want to do through iptables is limit access to port 7500 to those networks on
the access list. I want the remaining networking ports to remain operational,
as they are now. I would have made these restrictions on one of the
external firewalling devices rather than on the local machine had this been
possible.
Regards,
Mark.
--
Mark Hobley,
393 Quinton Road West,
Quinton, BIRMINGHAM.
B32 1QE.
|