Advantage Pro: Enquiry@vectratech - in 91-44-28263529 /30
Advantage Pro: Enquiry@vectratech - in 91-44-28263529 /30
TYPES OF FIREWALL
>>Hardware Firewal
>>Software Firewall
HARDWARE FIREWALL:
Sonypix, Checkpoint, Cisco. Etc
SOFTWATE FIREWALL:
1. iptables
(Linux)
2. ipsec (Default in windows)
3 .ipchains (RedHat 8)
• IPFSWADM
ipfwadm firewall used in kernel 2.0
• IPCHAIN
ipchains firewall used in kernel 2.2
• IPTABLES
iptables firewall used in kernel 2.4
TABLE NAME
Filter
Nat
Mangle
CHAIN
INPUT
OUTPUT
FORWARD
PREROUTING
POSTROUTING
TARGET
ACCEPT
DROP
REJECT
SNAT
DNAT
LOG
MASQUERADE
NAT X X
MANGLE
100.0.0.1 200.0.0.1
ISP
eth0:1
eth0
eth0
eth0
10.0.0.2 192.168.0.2
255.255.255.0 NEW
CHENNAI 255.0.0.0
192.168.0.1 YORK
CLIENT 10.0.0.1 CLIENT
(gw) (gw)
Using netconifg
Assigninig ip- Netconfig
commandcommand
assignis
address in used to ip-address
assign multiple
chennaiserver . ipaddress
Select yes to
assign ip-address
Assign ip-address
for eth0:1 here
View the
ipaddress using ip
a command
Permanent gateway is
added
To update the
ipforwarding use
sysctl –p command
Select eth0
Using netconifg
command assign
ip-address
Assigninig ip-
address in ISPserver
.
Assing ip address
for eth0:1
eth0:1 ip address is
assigned here
View the
ipaddress using ip
a command
Permanent gw is
assigned here
To update the
ipforwarding use
sysctl –p command
To update the
ipforwarding use
sysctl –p command
Use netconfig
Assign the ip-address command to assign
for newyork server ip-address
Set temporary
raouting
Permanent gw is
added
To enable ip-forwarding
open sysctl.conf file
Enable ipforward =1
To update the
ipforwarding use
sysctl –p command
Use system-config-
Assign the ip-address network-tui
for newyork client command
Click eth0
Check default gw is
added or not.
Network connectivity
is there
Network connectivity
will be available.
In chennai server
Writing the rule to
writing rule to accept
accept the icmp input
the input
from 192.168.0.0/24
network
At presently in newyork
client
There is a network
connectivity between
newyork client and chennai
client
0% packet loss
If theWriting
source the rule to
is 10.0.0.0/8
accept the tcp protocol
and destination is
Source is 192.168.0.0/24 192.168.0.0/24 (request)ssh
destination is 10.0.0.0/8 (tcp)will accept .
protocol(request) will
accept
Network connectivity
between newyork server and
chennai server also
connected.
So there is a connectivity
between chennai server and
newyork client
There is no network
connectivity between newyork
server and chennai server.
Newyorkclient is connected
with chennai client
All the network can
communicate
Connecting to chennai
server from new york client
Now it is redirected to
chennai client
Now we are in
chennai client.