HostedDB - Dedicated UNIX Servers

Securing-Optimizing-RH-Linux-1_2_140
Comments and suggestions concerning this book should be mailed to gmourani@videotron.ca © Copyright 1999-2000 Gerhard Mourani and Open Network Architecture ® 140     ipchains -A output -i $EXTERNAL_INTERFACE -p udp \              -s $IPADDR $UNPRIVPORTS \              -d $ANYWHERE 4000 -j ACCEPT       # ------------------------------------------------------------------     # FTP client (20, 21)     # -------------------     # outgoing request     ipchains -A input  -i $EXTERNAL_INTERFACE -p tcp ! -y \              -s $ANYWHERE 21 \              -d $IPADDR $UNPRIVPORTS -j ACCEPT       ipchains -A output -i $EXTERNAL_INTERFACE -p tcp \              -s $IPADDR $UNPRIVPORTS \              -d $ANYWHERE 21 -j ACCEPT       # NORMAL mode data channel     ipchains -A input  -i $EXTERNAL_INTERFACE -p tcp \             -s $ANYWHERE 20 \             -d $IPADDR $UNPRIVPORTS -j ACCEPT       # NORMAL mode data channel responses      ipchains -A output -i $EXTERNAL_INTERFACE -p tcp ! -y \             -s $IPADDR $UNPRIVPORTS \             -d $ANYWHERE 20 -j ACCEPT       # PASSIVE mode data channel creation     ipchains -A output -i $EXTERNAL_INTERFACE -p tcp \             -s $IPADDR $UNPRIVPORTS \             -d $ANYWHERE $UNPRIVPORTS -j ACCEPT       # PASSIVE mode data channel responses      ipchains -A input  -i $EXTERNAL_INTERFACE -p tcp ! -y \             -s $ANYWHERE $UNPRIVPORTS \             -d $IPADDR $UNPRIVPORTS -j ACCEPT       # ------------------------------------------------------------------     # RealAudio / QuickTime client     # ----------------------------     ipchains -A input  -i $EXTERNAL_INTERFACE -p tcp ! -y \              -s $ANYWHERE 554 \              -d $IPADDR $UNPRIVPORTS -j ACCEPT     ipchains -A output -i $EXTERNAL_INTERFACE -p tcp \              -s $IPADDR $UNPRIVPORTS \              -d $ANYWHERE 554 -j ACCEPT     # TCP is a more secure method:  7070:7071     ipchains -A input  -i $EXTERNAL_INTERFACE -p tcp ! -y \              -s $ANYWHERE 7070:7071 \              -d $IPADDR $UNPRIVPORTS -j ACCEPT     ipchains -A output -i $EXTERNAL_INTERFACE -p tcp \              -s $IPADDR $UNPRIVPORTS \              -d $ANYWHERE 7070:7071 -j ACCEPT