With my server,
I've simply got MonMotha's IPTABLES firewall script, a BIND DNS server
forwarding to my ISPs servers ++ a PHP connect/disconnect interface.

If you'd like the little PHP script, email me :)


On Wed, 2003-03-19 at 20:35, t wrote:
> Hi
> I have a dial up connection and want to use linux to connect to the net,
> then have windows
> boxs hanging off it.  I just looked at the
> "Masquerading Made Simple HOWTO"
> and it says to do the following
> modprobe ipt_MASQUERADE # If this fails, try continuing anyway
> iptables -F; iptables -t nat -F; iptables -t mangle -F
> iptables -t nat -A POSTROUTING -o ppp0 -j MASQUERADE
> echo 1 > /proc/sys/net/ipv4/ip_forward
>  iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
> iptables -A INPUT -m state --state NEW -i ! ppp0 -j ACCEPT
>  iptables -P INPUT DROP   #only if the first two are succesful
>  iptables -A FORWARD -i ppp0 -o ppp0 -j REJECT
> Before I do it, do you think it is very secure? All I want to be able to do
> through the
> linux box from the windows machines at the moment is to surf the net,
> collect/send mail
> and ssh out(I dont want to be able to ssh to this box from the net).  What
> do I need to
> add to allow only the services to/from the net.
> Thanks for your help
> Tony


"In a world without fences, who needs GATES?"

