iptables firewall
anyone have any experience w/ setting up a minimalist iptables firewall?
i currently have NAT/masquerade set up, but the machine acting as a firewall is open to the world.
what I would like to do is maintain nat functionality, but block off all incoming traffic on ports other than ssh, web, ssl web, ssl imap, etc. playing around w/ iptables and the HOWTOs, etc, i seem to keep getting to the point wehre I'm blocking outgoing traffic, which is not at all desired.
|