|
----- Original Message -----
From: Daniel El�as
Robles
Sent: Thursday, March 14, 2002 5:56 PM
Subject: RE: This might be a stupid question... The OUTPUT rules is for packets originated in you
firewall box, then this rule you tell us does not work as you
expect.
In order to avoid that you need to set a rule like
this.
iptables -I FORWARD -d 63.211.210.20 -i
internal_interface -j DROP
This way packets traversing the kernel into a
different destination will be droped in the first moment they are
checked.
You need to take care of the order you place the
rules in your script, that is why I inserted the rule, so it is the first rule
check in the FORWARD chain.
Hope this helps.
Daniel
|
