IPTABLES + XDMCP

Обсуждение настройки и работы сервисов, резервирования, сетевых настроек и вопросов безопасности ОС.

Модераторы: SLEDopit, Модераторы разделов

Аватара пользователя
Xenar
Сообщения: 30
ОС: Ubuntu 8.04

IPTABLES + XDMCP

Сообщение Xenar »

Здравствуйте, шибко помощи прошу, сам похоже не справляюсь. Организовал терминал серевер на Kubunte 7.10, (OpenVPN+XDMCP+vnc4server) удаленные клиенты цепляються к нему через инет. Все замечательно работает, но только до поднятия файровела, После этого в vncviever показывает голый X Window - то есть насколько я разобралься конект не доходит до XDMCP. Но порты 177 и 6000 включены.
Вот настойка iptables (взял из OpenVPN и немного изменил)

Код: Выделить всё

#!/bin/bash

# A Sample OpenVPN-aware firewall.

# eth0 is connected to the internet.
# eth1 is connected to a private subnet.

# Change this subnet to correspond to your private
# ethernet subnet.  Home will use HOME_NET/24 and
# Office will use OFFICE_NET/24.
PRIVATE=10.8.0.0/24

# Loopback address
LOOP=127.0.0.1

# Delete old iptables rules
# and temporarily block all traffic.
iptables -P OUTPUT DROP
iptables -P INPUT DROP
iptables -P FORWARD DROP
iptables -F

# Set default policies
iptables -P OUTPUT ACCEPT
iptables -P INPUT DROP
iptables -P FORWARD DROP

# Prevent external packets from using loopback addr
iptables -A INPUT -i eth0 -s $LOOP -j DROP
iptables -A FORWARD -i eth0 -s $LOOP -j DROP
iptables -A INPUT -i eth0 -d $LOOP -j DROP
iptables -A FORWARD -i eth0 -d $LOOP -j DROP

# Всё прибывающее из Интернета должно иметь реальный интернет-адрес
iptables -A FORWARD -i eth0 -s 192.168.0.0/16 -j DROP
iptables -A FORWARD -i eth0 -s 172.16.0.0/12 -j DROP
iptables -A FORWARD -i eth0 -s 10.0.0.0/8 -j DROP
iptables -A INPUT -i eth0 -s 192.168.0.0/16 -j DROP
iptables -A INPUT -i eth0 -s 172.16.0.0/12 -j DROP
iptables -A INPUT -i eth0 -s 10.0.0.0/8 -j DROP


# Блокировать исходящий NetBios (если Вы имеете Windows машины работающие в частной подсети).
# Это не будет затрагивать движения NetBios, которое течет по туннелю VPN,
# но это будет мешать местным Windows машинам передать себя в Интернетт
iptables -A FORWARD -p tcp --sport 137:139 -o eth0 -j DROP
iptables -A FORWARD -p udp --sport 137:139 -o eth0 -j DROP
iptables -A OUTPUT -p tcp --sport 137:139 -o eth0 -j DROP
iptables -A OUTPUT -p udp --sport 137:139 -o eth0 -j DROP

# Check source address validity on packets going out to internet
iptables -A FORWARD -s ! $PRIVATE -i eth1 -j DROP

# Allow local loopback
iptables -A INPUT -s $LOOP -j ACCEPT
iptables -A INPUT -d $LOOP -j ACCEPT

# Allow incoming pings (can be disabled)
iptables -A INPUT -p icmp --icmp-type echo-request -j ACCEPT

# Allow services such as www and ssh (can be disabled)
iptables -A INPUT -p tcp --dport http -j ACCEPT
iptables -A INPUT -p tcp --dport ssh -j ACCEPT

# Разрешить XDMCP
iptables -A INPUT -p udp --dport 177 -j ACCEPT
iptables -A INPUT -p tcp --dport 6000 -j ACCEPT
#iptables -A INPUT -p tcp --dport 7100 -j ACCEPT
#iptables -A OUTPUT -p tcp -m tcp --sport 177 -j ACCEPT
#iptables -A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 7100 --tcp-flags SYN,RST,ACK SYN -j REJECT --reject-with icmp-port-unreachable


# Allow incoming OpenVPN packets
# Duplicate the line below for each
# OpenVPN tunnel, changing --dport n
# to match the OpenVPN UDP port.
#
# In OpenVPN, the port number is
# controlled by the --port n option.
# If you put this option in the config
# file, you can remove the leading '--'
#
# If you taking the stateful firewall
# approach (see the OpenVPN HOWTO),
# then comment out the line below.

iptables -A INPUT -p udp --dport 1194 -j ACCEPT
iptables -A INPUT -p tcp --dport 1194 -j ACCEPT

# Allow packets from TUN/TAP devices.
# When OpenVPN is run in a secure mode,
# it will authenticate packets prior
# to their arriving on a tun or tap
# interface.  Therefore, it is not
# necessary to add any filters here,
# unless you want to restrict the
# type of packets which can flow over
# the tunnel.

iptables -A INPUT -i tun+ -j ACCEPT
iptables -A FORWARD -i tun+ -j ACCEPT
iptables -A INPUT -i tap+ -j ACCEPT
iptables -A FORWARD -i tap+ -j ACCEPT

# Allow packets from private subnets
iptables -A INPUT -i eth1 -j ACCEPT
iptables -A FORWARD -i eth1 -j ACCEPT

# Keep state of connections from local machine and private subnets
iptables -A OUTPUT -m state --state NEW -o eth0 -j ACCEPT
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A FORWARD -m state --state NEW -o eth0 -j ACCEPT
iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT



вот iptables -L

Код: Выделить всё

Chain INPUT (policy DROP)
target     prot opt source               destination
DROP       0    --  localhost            anywhere
DROP       0    --  anywhere             localhost
DROP       0    --  192.168.0.0/16       anywhere
DROP       0    --  172.16.0.0/12        anywhere
DROP       0    --  10.0.0.0/8           anywhere
ACCEPT     0    --  localhost            anywhere
ACCEPT     0    --  anywhere             localhost
ACCEPT     icmp --  anywhere             anywhere            icmp echo-request
ACCEPT     tcp  --  anywhere             anywhere            tcp dpt:www
ACCEPT     tcp  --  anywhere             anywhere            tcp dpt:ssh
ACCEPT     udp  --  anywhere             anywhere            udp dpt:xdmcp
ACCEPT     tcp  --  anywhere             anywhere            tcp dpt:x11
ACCEPT     udp  --  anywhere             anywhere            udp dpt:openvpn
ACCEPT     tcp  --  anywhere             anywhere            tcp dpt:openvpn
ACCEPT     0    --  anywhere             anywhere
ACCEPT     0    --  anywhere             anywhere
ACCEPT     0    --  anywhere             anywhere
ACCEPT     0    --  anywhere             anywhere            state RELATED,ESTABLISHED

Chain FORWARD (policy DROP)
target     prot opt source               destination
DROP       0    --  localhost            anywhere
DROP       0    --  anywhere             localhost
DROP       0    --  192.168.0.0/16       anywhere
DROP       0    --  172.16.0.0/12        anywhere
DROP       0    --  10.0.0.0/8           anywhere
DROP       tcp  --  anywhere             anywhere            tcp spts:netbios-ns:netbios-ssn
DROP       udp  --  anywhere             anywhere            udp spts:netbios-ns:netbios-ssn
DROP       0    -- !10.8.0.0/24          anywhere
ACCEPT     0    --  anywhere             anywhere
ACCEPT     0    --  anywhere             anywhere
ACCEPT     0    --  anywhere             anywhere
ACCEPT     0    --  anywhere             anywhere            state NEW
ACCEPT     0    --  anywhere             anywhere            state RELATED,ESTABLISHED

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination
DROP       tcp  --  anywhere             anywhere            tcp spts:netbios-ns:netbios-ssn
DROP       udp  --  anywhere             anywhere            udp spts:netbios-ns:netbios-ssn
ACCEPT     0    --  anywhere             anywhere            state NEW


помогите пожалуста где ошибка?
Мир спасет красота ..... и массовые расстрелы
Спасибо сказали: