Ubuntu Forums Archive Viewer

Open internal access to machine, but close it up outside network

Archived thread 1010053 from Security. Markdown source: Security/thread_1010053_Open_internal_access_to_machine,_but_close_it_up_o.md

Original URL About this archive
#1

Hi,

I am having a bit of a problem learning about firewalls and iptables. Here is my situation.

Internally, I want all default ports open for my other machines. I want them to be able to access my shares, printer, everything that is open by default. So, I want my subnet to be wide open. Anything on 192.168.mysubnet.X I want to have free reign.

Externally, I want to button it all up. Only allow what I need from the outside (ftp, ssh, http and vnc)

How would I go about it? I'm sure it's easy to do, no? I searched, but I rely on my friends here to help.

Thanks!

Jeremy

#2

First, as you may know, a router will do this for you.

If you are making your own router, we need more details.

You may want to start with ufw or gufw