does netfilter-persistent reload open up the gates for half a moment?What is the best solution for traffic control in a large system (ca. 2000 users)?Reduce firewall rules by half - one iptables rule for tcp and udpiptables/netfilter rules for samba/netbios accessAdd custom NAT rule to Plesk managed firewallHow to blacklist or whitelist lots or few ip ranges with ipset and iptables + fail2banRouting all traffic from a client with changing local subnet over VPNWhat is the destination of the spoofed source ip packet in terms of the netfilter chains?netfilter-persistent debian jessie ipv6 issueIPTables + Limit module: Why doesn't limit-burst get completely used?how to forward ports through multiple hops with iptables
Divisor Rich and Poor Numbers
What would be the game balance implications for using the Gygax method for applying falling damage?
Told to apply for UK visa before other visas, on UK-Spain-etc. visit
How does this piece of code determine array size without using sizeof( )?
Can the word crowd refer to just 10 people?
Does the usage of mathematical symbols work differently in books than in theses?
Why wear sunglasses in indoor velodromes?
Using `printf` to print variable containing `%` percent sign results in "bash: printf: `p': invalid format character"
Working hours and productivity expectations for game artists and programmers
Should all adjustments be random effects in a mixed linear effect?
Why didn't Daenerys' advisers suggest assassinating Cersei?
What's is the easiest way to purchase a stock and hold it
What do you call bracelets you wear around the legs?
Can an airline pilot be prosecuted for killing an unruly passenger who could not be physically restrained?
In Dutch history two people are referred to as "William III"; are there any more cases where this happens?
Does the US Supreme Court vote using secret ballots?
Why are stats in Angband written as 18/** instead of 19, 20...?
Why is so much ransomware breakable?
How to customize the pie chart background in PowerPoint?
Failing students when it might cause them economic ruin
Appropriate liquid/solvent for life in my underground environment on Venus
Why is Drogon so much better in battle than Rhaegal and Viserion?
Why are there five extra turns in tournament Magic?
How to pipe results multiple results into a command?
does netfilter-persistent reload open up the gates for half a moment?
What is the best solution for traffic control in a large system (ca. 2000 users)?Reduce firewall rules by half - one iptables rule for tcp and udpiptables/netfilter rules for samba/netbios accessAdd custom NAT rule to Plesk managed firewallHow to blacklist or whitelist lots or few ip ranges with ipset and iptables + fail2banRouting all traffic from a client with changing local subnet over VPNWhat is the destination of the spoofed source ip packet in terms of the netfilter chains?netfilter-persistent debian jessie ipv6 issueIPTables + Limit module: Why doesn't limit-burst get completely used?how to forward ports through multiple hops with iptables
.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;
I have iptables set up to block all outgoing traffic that tries escape outside my VPN connection. and netfilter-persistent to make iptables rules persistent. this all works perfectly.
Now because connecting IPs change from time to time, I want to make a script that looks up IPs and updates iptables whitelist rules on an hourly basis.
Two related questions on this..
- Whenever the script reloads the netfilter-persistent service to update iptables, is there a split second where traffic could escape outside VPN? or are new rules overwritten without a full flush first?
- and how about during a system reboot? do the network interfaces come up before netfilter-persistent kicks in or is there a possibility for non-VPN traffic to escape during boot-up?
I feel it's only logical in both cases it should be safe from 'leakage' , but couldn't find anything confirming this.
iptables vpn firewall
add a comment |
I have iptables set up to block all outgoing traffic that tries escape outside my VPN connection. and netfilter-persistent to make iptables rules persistent. this all works perfectly.
Now because connecting IPs change from time to time, I want to make a script that looks up IPs and updates iptables whitelist rules on an hourly basis.
Two related questions on this..
- Whenever the script reloads the netfilter-persistent service to update iptables, is there a split second where traffic could escape outside VPN? or are new rules overwritten without a full flush first?
- and how about during a system reboot? do the network interfaces come up before netfilter-persistent kicks in or is there a possibility for non-VPN traffic to escape during boot-up?
I feel it's only logical in both cases it should be safe from 'leakage' , but couldn't find anything confirming this.
iptables vpn firewall
add a comment |
I have iptables set up to block all outgoing traffic that tries escape outside my VPN connection. and netfilter-persistent to make iptables rules persistent. this all works perfectly.
Now because connecting IPs change from time to time, I want to make a script that looks up IPs and updates iptables whitelist rules on an hourly basis.
Two related questions on this..
- Whenever the script reloads the netfilter-persistent service to update iptables, is there a split second where traffic could escape outside VPN? or are new rules overwritten without a full flush first?
- and how about during a system reboot? do the network interfaces come up before netfilter-persistent kicks in or is there a possibility for non-VPN traffic to escape during boot-up?
I feel it's only logical in both cases it should be safe from 'leakage' , but couldn't find anything confirming this.
iptables vpn firewall
I have iptables set up to block all outgoing traffic that tries escape outside my VPN connection. and netfilter-persistent to make iptables rules persistent. this all works perfectly.
Now because connecting IPs change from time to time, I want to make a script that looks up IPs and updates iptables whitelist rules on an hourly basis.
Two related questions on this..
- Whenever the script reloads the netfilter-persistent service to update iptables, is there a split second where traffic could escape outside VPN? or are new rules overwritten without a full flush first?
- and how about during a system reboot? do the network interfaces come up before netfilter-persistent kicks in or is there a possibility for non-VPN traffic to escape during boot-up?
I feel it's only logical in both cases it should be safe from 'leakage' , but couldn't find anything confirming this.
iptables vpn firewall
iptables vpn firewall
asked May 6 at 7:27
JowskiJowski
83
83
add a comment |
add a comment |
1 Answer
1
active
oldest
votes
- Netfilter-persistent scripts use
iptables-restore
tool, that makes atomic reloading of an iptables rule set. - Netfilter-persistent scripts during a boot are run before interfaces will be bringing up (you can check output of
systemctl cat netfilter-persistent.service
).
add a comment |
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "2"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f966003%2fdoes-netfilter-persistent-reload-open-up-the-gates-for-half-a-moment%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
1 Answer
1
active
oldest
votes
1 Answer
1
active
oldest
votes
active
oldest
votes
active
oldest
votes
- Netfilter-persistent scripts use
iptables-restore
tool, that makes atomic reloading of an iptables rule set. - Netfilter-persistent scripts during a boot are run before interfaces will be bringing up (you can check output of
systemctl cat netfilter-persistent.service
).
add a comment |
- Netfilter-persistent scripts use
iptables-restore
tool, that makes atomic reloading of an iptables rule set. - Netfilter-persistent scripts during a boot are run before interfaces will be bringing up (you can check output of
systemctl cat netfilter-persistent.service
).
add a comment |
- Netfilter-persistent scripts use
iptables-restore
tool, that makes atomic reloading of an iptables rule set. - Netfilter-persistent scripts during a boot are run before interfaces will be bringing up (you can check output of
systemctl cat netfilter-persistent.service
).
- Netfilter-persistent scripts use
iptables-restore
tool, that makes atomic reloading of an iptables rule set. - Netfilter-persistent scripts during a boot are run before interfaces will be bringing up (you can check output of
systemctl cat netfilter-persistent.service
).
answered May 6 at 8:28
Anton DanilovAnton Danilov
90357
90357
add a comment |
add a comment |
Thanks for contributing an answer to Server Fault!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f966003%2fdoes-netfilter-persistent-reload-open-up-the-gates-for-half-a-moment%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown