iptables – blocking incoming traffic
Feb 14
2009
2009
Comments Off
This iptables config will block all incoming traffic, except from machines, identified by thier MAC addresses:
iptables -F INPUT
iptables -A INPUT -m mac—mac-source 00:3f:5f:ab:2c:7d -j ACCEPT
iptables -A INPUT -m mac—mac-source 00:1e:32:36:97:4a -j ACCEPT
iptables -A INPUT -m mac—mac-source 00:44:11:a5:1d:6d -j ACCEPT
# or by ip address:
#iptables -A INPUT -p tcp -s 1.1.1.1 -j ACCEPT
#iptables -A INPUT -p tcp -s 2.2.2.2 -j ACCEPT
#iptables -A INPUT -p tcp -s 3.3.3.3 -j ACCEPT
iptables -A INPUT -m state—state ESTABLISHED -j ACCEPT
iptables -A INPUT -s 127.0.0.1 -j ACCEPT
iptables -A INPUT -j REJECT