iptables help

jludwig wralphie at comcast.net
Thu Jul 15 18:43:11 UTC 2004


On Thu, 2004-07-15 at 13:54, Nina Pham wrote:
> hi, I put the log message into one of  my iptables  log rules. And it is 
> not happy about it and flush out everything. When I try to restart, or 
> restore, it complains about the log message and refuse to restore. How 
> do I get back that old iptables? Iptables now can't even run because of 
> that incorrect log message.
> 
> Thanks


Iptables was designed so if there was a rule(s) with an error(s) it
still loads all good rules.  So if you mess up a rule the rest will
still work.

Be forewarned though if a "valid bad rule such as;

< iptables -I OUTPUT -s 0/0 -j reject >

really gum up the works or leave a hole in your firewall.

Also rule order can be very important.
-- 
jludwig <wralphie at comcast.net>





More information about the fedora-list mailing list