Nie jesteś zalogowany.
Jeśli nie posiadasz konta, zarejestruj je już teraz! Pozwoli Ci ono w pełni korzystać z naszego serwisu. Spamerom dziękujemy!

Ogłoszenie

Prosimy o pomoc dla małej Julki — przekaż 1% podatku na Fundacji Dzieciom zdazyć z Pomocą.
Więcej informacji na dug.net.pl/pomagamy/.

#26  2014-10-16 13:13:47

  Jacekalex - Podobno człowiek...;)

Jacekalex
Podobno człowiek...;)
Skąd: /dev/urandom
Zarejestrowany: 2008-01-07

Re: Czasowe reguły iptables

To naprawdę dobra wiadomość :D.
Możesz z resztą ubić wszystkie połączenia, bo prawdopodobnie wiszą w regułach zawierających RELATED,ESTABLISHED, dlatego nie znikają od razu.


Trzeba by tylko wszystkie reguły dotyczące kontroli stanu pakietu objąć takimi samymi warunkami, jak INPUT i OUTPUT, czyli jest z tym trochę dodatkowej zabawy.

Przy czym nie ma różnicy, czy w skrypcie Crona, czy regułami w FW, bo sytuacja z nawiązanymi i kontynuowanymi połączeniami w obu przypadkach będzie wyglądała identycznie.


W demokracji każdy naród ma taką władzę, na jaką zasługuje ;)
Si vis pacem  para bellum  ;)       |       Pozdrawiam :)

Offline

 

#27  2014-10-16 16:46:50

  morfik - Cenzor wirtualnego świata

morfik
Cenzor wirtualnego świata
Skąd: ze WSI
Zarejestrowany: 2011-09-15
Serwis

Re: Czasowe reguły iptables

Ja nieco przerobiłem swój skrypt iptables i ostatecznie to wygląda tak:

Kod:

    iptables -t filter -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED,NEW -m mark --mark 5 -j time-p2p
    iptables -t filter -A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
        ...

    iptables -t filter -A OUTPUT -m conntrack --ctstate ESTABLISHED,RELATE,NEW -m cgroup --cgroup 5 -j time-p2p
    iptables -t filter -A OUTPUT -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT
        ...

    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 0:03:30 --timestop 0:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 1:03:30 --timestop 1:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 2:03:30 --timestop 2:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 3:03:30 --timestop 3:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 4:03:30 --timestop 4:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 5:03:30 --timestop 5:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 6:03:30 --timestop 6:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 7:03:30 --timestop 7:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 8:03:30 --timestop 8:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 9:03:30 --timestop 9:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 10:03:30 --timestop 10:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 11:03:30 --timestop 11:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 12:03:30 --timestop 12:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 13:03:30 --timestop 13:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 14:03:30 --timestop 14:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 15:03:30 --timestop 15:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 16:03:30 --timestop 16:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 17:03:30 --timestop 17:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 18:03:30 --timestop 18:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 19:03:30 --timestop 19:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 20:03:30 --timestop 20:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 21:03:30 --timestop 21:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 22:03:30 --timestop 22:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -m time --weekdays 1,2,3,4,5,6,7 --timestart 23:03:30 --timestop 23:58:00 --kerneltz -j ACCEPT
    iptables -t filter -A time-p2p -j DROP

Narazie testuje i póki co jest wszystko zgodnie z planem:


Kod:

Chain time-p2p (2 references)
 pkts bytes target     prot opt in     out     source               destination
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 00:03:30 to 00:58:00
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 01:03:30 to 01:58:00
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 02:03:30 to 02:58:00
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 03:03:30 to 03:58:00
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 04:03:30 to 04:58:00
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 05:03:30 to 05:58:00
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 06:03:30 to 06:58:00
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 07:03:30 to 07:58:00
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 08:03:30 to 08:58:00
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 09:03:30 to 09:58:00
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 10:03:30 to 10:58:00
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 11:03:30 to 11:58:00
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 12:03:30 to 12:58:00
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 13:03:30 to 13:58:00
2048K 1498M ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 14:03:30 to 14:58:00
 456K  149M ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 15:03:30 to 15:58:00
 323K  130M ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 16:03:30 to 16:58:00
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 17:03:30 to 17:58:00
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 18:03:30 to 18:58:00
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 19:03:30 to 19:58:00
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 20:03:30 to 20:58:00
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 21:03:30 to 21:58:00
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 22:03:30 to 22:58:00
    0     0 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            TIME from 23:03:30 to 23:58:00
20016 1509K DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0

Możesz z resztą ubić wszystkie połączenia, bo prawdopodobnie wiszą w regułach zawierających RELATED,ESTABLISHED, dlatego nie znikają od razu.[/quote]
A jak je ubić?

Offline

 

Stopka forum

Powered by PunBB
© Copyright 2002–2005 Rickard Andersson
To nie jest tylko forum, to nasza mała ojczyzna ;-)

[ Generated in 0.010 seconds, 11 queries executed ]

Informacje debugowania

Time (s) Query
0.00009 SET CHARSET latin2
0.00004 SET NAMES latin2
0.00098 SELECT u.*, g.*, o.logged FROM punbb_users AS u INNER JOIN punbb_groups AS g ON u.group_id=g.g_id LEFT JOIN punbb_online AS o ON o.ident='3.140.185.194' WHERE u.id=1
0.00073 REPLACE INTO punbb_online (user_id, ident, logged) VALUES(1, '3.140.185.194', 1732815316)
0.00075 SELECT * FROM punbb_online WHERE logged<1732815016
0.00063 SELECT topic_id FROM punbb_posts WHERE id=277660
0.00008 SELECT id FROM punbb_posts WHERE topic_id=26550 ORDER BY posted
0.00077 SELECT t.subject, t.closed, t.num_replies, t.sticky, f.id AS forum_id, f.forum_name, f.moderators, fp.post_replies, 0 FROM punbb_topics AS t INNER JOIN punbb_forums AS f ON f.id=t.forum_id LEFT JOIN punbb_forum_perms AS fp ON (fp.forum_id=f.id AND fp.group_id=3) WHERE (fp.read_forum IS NULL OR fp.read_forum=1) AND t.id=26550 AND t.moved_to IS NULL
0.00007 SELECT search_for, replace_with FROM punbb_censoring
0.00321 SELECT u.email, u.title, u.url, u.location, u.use_avatar, u.signature, u.email_setting, u.num_posts, u.registered, u.admin_note, p.id, p.poster AS username, p.poster_id, p.poster_ip, p.poster_email, p.message, p.hide_smilies, p.posted, p.edited, p.edited_by, g.g_id, g.g_user_title, o.user_id AS is_online FROM punbb_posts AS p INNER JOIN punbb_users AS u ON u.id=p.poster_id INNER JOIN punbb_groups AS g ON g.g_id=u.group_id LEFT JOIN punbb_online AS o ON (o.user_id=u.id AND o.user_id!=1 AND o.idle=0) WHERE p.topic_id=26550 ORDER BY p.id LIMIT 25,25
0.00095 UPDATE punbb_topics SET num_views=num_views+1 WHERE id=26550
Total query time: 0.0083 s