OpenVZ Forum


Home » General » Support » iptables do not append rules
iptables do not append rules [message #52088] Sun, 14 June 2015 01:14 Go to next message
andrex is currently offline  andrex
Messages: 2
Registered: June 2015
Junior Member
I want to make a set of rules on iptables inside of a node, but it seems that the iptables isn't appending all the rules or somehow and kick me out everytime I run the script:

# Allow connections that are already connected to your server
iptables -A INPUT -i venet0 -m state --state ESTABLISHED,RELATED -j ACCEPT

# Allow connections to SSH
iptables -A INPUT -p tcp --dport 22 -m state --state NEW -j ACCEPT

# Allowing connections to HTTP/HTTPS
iptables -A INPUT -p tcp --dport 80 -m state --state NEW -j ACCEPT
iptables -A INPUT -p tcp --dport 443 -m state --state NEW -j ACCEPT

# Allow icmp input but limit it to 10/sec
iptables -A INPUT -p icmp -m limit --limit 10/second -j ACCEPT
iptables -A INPUT -p icmp -j ACCEPT

# Allow all incoming traffic from local
iptables -A INPUT -i lo -j ACCEPT

# Changing the default policy for INPUT chain
iptables -A INPUT -j DROP


I already change the conf for vz:
IPTABLES_MODULES="ipt_REJECT ipt_tos ipt_limit ipt_multiport iptable_filter iptable_mangle ipt_TCPMSS ipt_tcpmss ipt_ttl ipt_length ipt_state xt_state ip_conntrack"

Any help with this is aprecciated.

Thanks.
Re: iptables do not append rules [message #52196 is a reply to message #52088] Mon, 07 September 2015 17:31 Go to previous messageGo to next message
andrex is currently offline  andrex
Messages: 2
Registered: June 2015
Junior Member
Nobody? *bump*
Re: iptables do not append rules [message #52198 is a reply to message #52088] Sat, 12 September 2015 08:08 Go to previous message
curx
Messages: 739
Registered: February 2006
Location: Nürnberg, Germany
Senior Member

more info please:

- vzctl version
- ouput $ grep NETFILTER /etc/vz/con/<ctid>.conf # ctid=container id
- can you enter ct via vzctl enter and apply the iptables rules

Previous Topic: Vzdump Files missing
Next Topic: yum update kernel error
Goto Forum:
  


Current Time: Thu Apr 25 07:37:01 GMT 2024

Total time taken to generate the page: 0.01587 seconds