SixXS::Sunset 2017-06-06

Need help in Firewall setup
[nl] Shadow Hawkins on Friday, 03 May 2013 16:40:59
I tried to setup the more sophistcated firewall from here: http://www.sixxs.net/wiki/IPv6_Firewalling#Example_script_for_IPv6_stateless_firewall Unfortunatly somehowe I cannot be pinged by the pop (rest works OK) This is what ip6tables -L gives me: root@raspberrypi:/usr/local/bin# ip6tables -L Chain INPUT (policy DROP) target prot opt source destination DROP udp anywhere anywhere DROP tcp anywhere anywhere tcpflags: FIN,SYN,RST,ACK/SYN DROP all anywhere anywhere rt type:0 segsleft:0 ACCEPT all anywhere anywhere ACCEPT all anywhere anywhere state RELATED,ESTABLISHED ACCEPT all anywhere anywhere ACCEPT all fe80::/10 anywhere ACCEPT all anywhere ip6-mcastprefix/8 AllowICMPs ipv6-icmp 2001:960:63d::1/128 cl-1598.ams-04.nl.sixxs.net/128 LOG all anywhere anywhere LOG level warning prefix "INPUT-v6:" Chain FORWARD (policy DROP) target prot opt source destination DROP udp anywhere anywhere DROP tcp anywhere anywhere tcpflags: FIN,SYN,RST,ACK/SYN DROP all anywhere anywhere rt type:0 segsleft:0 ACCEPT all 2001:960:660::/48 anywhere state NEW ACCEPT all anywhere anywhere state RELATED,ESTABLISHED LOG all anywhere anywhere LOG level warning prefix "FORWARD-v6:" Chain OUTPUT (policy DROP) target prot opt source destination DROP all anywhere anywhere rt type:0 segsleft:0 ACCEPT all anywhere anywhere ACCEPT all anywhere anywhere ACCEPT all anywhere anywhere ACCEPT all fe80::/10 anywhere ACCEPT all anywhere ip6-mcastprefix/8 LOG all anywhere anywhere LOG level warning prefix "OUTPUT-v6:" Chain AllowICMPs (1 references) target prot opt source destination ACCEPT ipv6-icmp anywhere anywhere ipv6-icmp destination-unreachable ACCEPT ipv6-icmp anywhere anywhere ipv6-icmp packet-too-big ACCEPT ipv6-icmp anywhere anywhere ipv6-icmp time-exceeded ACCEPT ipv6-icmp anywhere anywhere ipv6-icmp parameter-problem ACCEPT ipv6-icmp anywhere anywhere ipv6-icmp echo-request limit: avg 5/sec burst 10 ACCEPT ipv6-icmp anywhere anywhere ipv6-icmp echo-reply root@raspberrypi:/usr/local/bin#
Need help in Firewall setup Solved
[nl] Shadow Hawkins on Friday, 03 May 2013 16:54:38
Solved: Made a typo!
Need help in Firewall setup
[ch] Jeroen Massar SixXS Staff on Saturday, 04 May 2013 06:56:12
Please note that you are dropping ICMP from all around the Internet, and that is a bad idea. Especially "Packet Too Big" is an important one, but various others should also be accepted, not just from the PoP side. That you are dropping "Destination Unreachable" will just mean that if a remote server is not active you will have to time out before noticing it is not there, which it told you too. There really is no reason to filter ICMP. And anyway, it is a much better idea to have no listening ports on your boxes and know what is running on them instead of giving yourself a half-broken Internet....

Please note Posting is only allowed when you are logged in.

Static Sunset Edition of SixXS
©2001-2017 SixXS - IPv6 Deployment & Tunnel Broker