Monday, October 14, 2013

Block All Outgoing Traffic from Server, Allowing Limited IPS Using Iptables

Can some one help me in the below requirement using iptables, 

Block all the traffic, allowing only said traffic. 

I tried below rule by googling, 

iptables -P OUTPUT DROP, which drops every thing, I could also see few rules which will allow only certain ips 

IIRC iptables syntax is a hell, so if possible swap to an OpenBSD firewall and use the simpler syntax of it's pf packet filtering firewall (it also in itself does NAT, round robin networking and much more and OpenBSD has relayed as I posted in another thread just a moment ago). I would actually recommend OpenBSD firewalls to almost anyone, except those who have the $ to pay for a decent Cisco or other good proprietary firewall, and not even then necessarily if there is someone competent with OpenBSD and pf. 


