{"id":82,"date":"2007-07-05T10:34:00","date_gmt":"2007-07-05T08:34:00","guid":{"rendered":"https:\/\/test.n3oxid.fr\/?p=82"},"modified":"2021-04-18T21:38:07","modified_gmt":"2021-04-18T19:38:07","slug":"netfilter-quelques-regles","status":"publish","type":"post","link":"https:\/\/www.n3oxid.fr\/?p=82","title":{"rendered":"NetFilter : quelques &#8220;r\u00e9gles&#8221;"},"content":{"rendered":"\n<p>Les deux premi\u00e8res le\u00e7ons \u00e0 retenir en ce qui concerne NetFilter&nbsp;:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Il faut toujours initialiser les cibles par d\u00e9faut, m\u00eame pour les cha\u00eenes des tables que nous ne pensons peut-\u00eatre pas utiliser. Il faut en toute situation conna\u00eetre l&#8217;\u00e9tat de de ces cibles. Un script Netfilter devrait donc toujours commencer par&nbsp;:<\/li><\/ul>\n\n\n\n<pre class=\"wp-block-preformatted\">     # Initialisation de la table FILTER<br>\n       <code>iptables -t filter -F<br><\/code>\n       <code>iptables -t filter -X<br><\/code>\n       <code>iptables -t filter -P INPUT   DROP<br><\/code>\n       <code>iptables -t filter -P OUTPUT  DROP<br><\/code>\n       <code>iptables -t filter -P FORWARD DROP<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-preformatted\">     # Initialisation de la table NAT<br>\n       <code>iptables -t nat -F<br><\/code>\n       <code>iptables -t nat -X <br><\/code>\n       <code>iptables -t nat -P PREROUTING  ACCEPT<br><\/code>\n       <code>iptables -t nat -P POSTROUTING ACCEPT<br><\/code>\n       <code>iptables -t nat -P OUTPUT      ACCEPT<\/code><\/pre>\n\n\n\n<pre class=\"wp-block-preformatted\">     # Initialisation de la table MANGLE<br>\n       <code>iptables -t mangle -F<br><\/code>\n       <code>iptables -t mangle -X <br><\/code>\n       <code>iptables -t mangle -P PREROUTING  ACCEPT<br><\/code>\n       <code>iptables -t mangle -P INPUT       ACCEPT<br><\/code>\n       <code>iptables -t mangle -P OUTPUT      ACCEPT<br><\/code>\n       <code>iptables -t mangle -P FORWARD     ACCEPT<br><\/code>\n       <code>iptables -t mangle -P POSTROUTING ACCEPT<\/code><\/pre>\n\n\n\n<ul class=\"wp-block-list\"><li>En cas de doute, utiliser la commande &#8220;iptables -L -v -t&nbsp;<a href=\"https:\/\/www.n3oxid.fr\/index.php\/post\/2007\/07\/05\/table\">table<\/a>&#8221; permettant d&#8217;obtenir bon nombre d&#8217;informations sur le nombre de paquets pour lesquels s&#8217;applique une r\u00e8gle ou un comportement par d\u00e9faut.<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Les deux premi\u00e8res le\u00e7ons \u00e0 retenir en ce qui concerne NetFilter&nbsp;: Il faut toujours initialiser les cibles par d\u00e9faut, m\u00eame pour les cha\u00eenes des tables que nous ne pensons peut-\u00eatre &#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[9,48],"class_list":["post-82","post","type-post","status-publish","format-standard","hentry","category-computing","tag-linux","tag-netfilter"],"_links":{"self":[{"href":"https:\/\/www.n3oxid.fr\/index.php?rest_route=\/wp\/v2\/posts\/82","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.n3oxid.fr\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.n3oxid.fr\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.n3oxid.fr\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.n3oxid.fr\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=82"}],"version-history":[{"count":1,"href":"https:\/\/www.n3oxid.fr\/index.php?rest_route=\/wp\/v2\/posts\/82\/revisions"}],"predecessor-version":[{"id":83,"href":"https:\/\/www.n3oxid.fr\/index.php?rest_route=\/wp\/v2\/posts\/82\/revisions\/83"}],"wp:attachment":[{"href":"https:\/\/www.n3oxid.fr\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=82"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.n3oxid.fr\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=82"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.n3oxid.fr\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=82"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}