tu.com/community/UFW
I'm also using UFW, but my needs are extremely simple:
* block all ports except for 53 UDP.
* block all traffic to port 22 except for $IPs
UFW makes this *really* simple.
-Jeremy
--fUYQa+Pmc3FrFX/N
Content-Type: application/pgp-signature
-----BEGIN PGP SIGNATURE-----
Version: GnuPG/MacGPG2 v2.0.18 (Darwin)
iQIcBAEBAgAGBQJQfZnZAAoJEL60QUljAMw9hDwQAOJCS3dfOhmlbTiPJp4ludaM
/mSQZWnICqFo8qsFm8SGMC83t7rzdYKV7Wyq2mFCT7uYdIPVM7FfVSTS5LKe1gm4
Q1kpsRtGx4RuDqVv6iDT36c/2yK38GbrjrmUDjmk9NOg+qYSvffHP5LC7MBObsF+
opf61wHTexCqXzrPDdmfpJ2po2sAmvg3FvByrqokG8zt83LhCf4gRO7smsvfNXx2
HKJKYmrzHnRPge3x2DAL1PuHills4i2Ywh3qqUoxKeASgsUNysPe1fadcbo1FBSR
rPjDoYhiLwaY+8/V1Nc4WkrbJ3R63jCrqG7mqFCaYY5K+/uOtCQTw0czopX2zAHL
pWMFz/gY/aHR7bv03kN/MPdleQXobngk/cO+VsYqbh4OB6AxFSEdKU7XRlPlwMyT
smnV1g5nUCYk30KcZk0wv+pjsdgi+OhcN8Seaxuj9u0qzJIMa6HhswjE15aFJWFL
qhZHPArkESYzePyvzjUGro3hlL5VNTXy9CcblQH+vG0IKtt88R/y5Po22GHU8s5a
lzYKHNxsHr464G0aE/vCFMPqkhsb+MTBA6wuqcC7y/fuecCTegwWflikByEEta2f
+UHYm7fUdqUCTPsRWUtnmyzPUZM+J6oLLb2yQ223xohSylEhjaPl9zQBkujS281t
4t9usVq+uqcq+Pgc8+S6
=8ID9
-----END PGP SIGNATURE-----
--fUYQa+Pmc3FrFX/N--
From andylockran@??? Tue Oct 16 17:40:06 2012
Received: from mail-wi0-f170.google.com ([209.85.212.170])
by mail.bitfolk.com with esmtps (TLS1.0:RSA_ARCFOUR_SHA1:16)
(Exim 4.72) (envelope-from <andylockran@???>)
id 1TOB7e-0007rE-Cs
for users@???; Tue, 16 Oct 2012 17:40:06 +0000
Received: by mail-wi0-f170.google.com with SMTP id hm2so162900wib.3
for <users@???>; Tue, 16 Oct 2012 10:39:59 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113;
h=content-type:mime-version:subject:from:in-reply-to:date
:content-transfer-encoding:message-id:references:to:x-mailer;
bh=wco4Zpl52msSlhz6bDIzCEt4GXBUAvAH/mOx0C/Mq84=;
b=MefkXejBFhc52gBeHo/OW7f1dBXWT5yfar4EdCbrnnLkbRET4ckW2l1Fplhw+46g9n
FlvUJSll46kf9Ois4HkYoXubkoKPYkwHzpZRrrPXGYwSNozT8DKhmCtphW0uMzlMvyiU
XiqOO2s2fVWTkPtx1GBA+sHylCX8bGVX+lbc5T/heP64S3AvZ7QoaJGXtggvck2ph3Oi
Q0Nx6Clv3KMy+bmSOZ3IfYY6BSViQL4zBU7LE/lPTOOzFRlI7dXsgIdEvPIxE7W9YFXz
PWLgV1ouBnCXlCaQnpGR6MIGSv28mvvYmFhIHPVGq3n6EAJ0l3cfLM/p9lvkucvJMcz0
yxBQ==
Received: by 10.216.70.13 with SMTP id o13mr10343099wed.184.1350409198979;
Tue, 16 Oct 2012 10:39:58 -0700 (PDT)
Received: from [10.20.210.29] ([82.113.183.190])
by mx.google.com with ESMTPS id eq2sm22842997wib.1.2012.10.16.10.39.56
(version=TLSv1/SSLv3 cipher=OTHER);
Tue, 16 Oct 2012 10:39:58 -0700 (PDT)
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Mac OS X Mail 6.2 \(1499\))
From: Andrew Loughran <andylockran@???>
In-Reply-To: <20121016173105.GA15979@???>
Date: Tue, 16 Oct 2012 18:40:08 +0100
Content-Transfer-Encoding: quoted-printable
Message-Id: <C4601CF3-2348-4B30-A168-BD115F11E45A@???>
References: <CA+q7HTwsEfGBwXVW9xANKWXSW8DB2uao+pjc5LekZC5gzYvP-w@???>
<507D5C4D.8000501@???>
<20121016173105.GA15979@???>
To: users@???
X-Mailer: Apple Mail (2.1499)
X-Virus-Scanner: Scanned by ClamAV on mail.bitfolk.com at Tue,
16 Oct 2012 17:40:06 +0000
X-SA-Exim-Connect-IP: 209.85.212.170
X-SA-Exim-Mail-From: andylockran@???
X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on
spamd2.lon.bitfolk.com
X-Spam-Level:
X-Spam-ASN: AS15169 209.85.212.0/24
X-Spam-Status: No, score=-0.8 required=5.0 tests=DKIM_SIGNED,DKIM_VALID,
DKIM_VALID_AU, RCVD_IN_DNSWL_LOW,
SPF_PASS shortcircuit=no autolearn=disabled version=3.3.1
X-Spam-Report: * -0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at
http://www.dnswl.org/, low * trust
* [209.85.212.170 listed in list.dnswl.org]
* -0.0 SPF_PASS SPF: sender matches SPF record
* -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from
author's * domain
* -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
* 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily
* valid
X-SA-Exim-Version: 4.2.1 (built Mon, 22 Mar 2010 06:51:10 +0000)
X-SA-Exim-Scanned: Yes (on mail.bitfolk.com)
Subject: Re: [bitfolk] iptables front-end?
X-BeenThere: users@???
X-Mailman-Version: 2.1.13
Precedence: list
List-Id: Users of BitFolk hosting <users.lists.bitfolk.com>
List-Unsubscribe: <https://lists.bitfolk.com/mailman/options/users>,
<mailto:users-request@lists.bitfolk.com?subject=unsubscribe>
List-Archive: <http://lists.bitfolk.com/lurker/list/users.html>
List-Post: <mailto:users@lists.bitfolk.com>
List-Help: <mailto:users-request@lists.bitfolk.com?subject=help>
List-Subscribe: <https://lists.bitfolk.com/mailman/listinfo/users>,
<mailto:users-request@lists.bitfolk.com?subject=subscribe>
X-List-Received-Date: Tue, 16 Oct 2012 17:40:07 -0000
I really like ufw, it's simple and does basic configuration great.
For more complicated setups, I've normally used shorewall, though not =
sure how well that is currently supported. That said, I did use ufw the =
other week to setup a wireless access point managed, that gave the =
administrator the ability to kick off MAC addresses that were using too =
much bandwidth.
Regards,
Andy
On 16 Oct 2012, at 18:31, Jeremy Kitchen <kitchen@???> wrote:
> On Tue, Oct 16, 2012 at 02:08:29PM +0100, Simon Bell wrote:
>> On 16/10/12 14:07, Barry Watson wrote:
>>> Hey there list,
>>>=20
>>> I'd be grateful if someone could recommend please a front-end for
>>> iptables? Arno's iptables seems well-regarded.
>>>=20
>>> I've set up some basic iptables rules on my VPS that allow/block
>>> various ports etc but want to be able to use iptable's state
>>> module too and would like to use a script that's been proved
>>> through use.
>>>=20
>>> Thanks in advance for any help/ideas.
>>>=20
>>> Barry
>>>=20
>> UFW
>>=20
>> https://help.ubuntu.com/community/UFW
>=20
> I'm also using UFW, but my needs are extremely simple:
>=20
> * block all ports except for 53 UDP.
> * block all traffic to port 22 except for $IPs
>=20
> UFW makes this *really* simple.
>=20
> -Jeremy
> _______________________________________________
> users mailing list
> users@???
> https://lists.bitfolk.com/mailman/listinfo/users
From stuart@??? Tue Oct 16 19:13:04 2012
Received: from numpty.absolutelyplastered.com ([85.119.82.19])
by mail.bitfolk.com with esmtp (Exim 4.72)
(envelope-from <stuart@???>) id 1TOCZc-00030i-Ru
for users@???; Tue, 16 Oct 2012 19:13:04 +0000
Received: from localhost (localhost.localdomain [127.0.0.1])
by numpty.absolutelyplastered.com (Postfix) with ESMTP id BBE46643E2
for <users@???>; Tue, 16 Oct 2012 19:04:09 +0000 (UTC)
X-Virus-Scanned: Debian amavisd-new at numpty.absolutelyplastered.com
Received: from numpty.absolutelyplastered.com ([127.0.