12.07.2015 Views

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

Red Hat Enterprise Linux 5 Administration Unleashed

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

480CHAPTER 24Configuring a FirewallTABLE 24.2ParameterContinuedDescription-i Interface on which the packet was received. If an exclamation pointand a space are before it, the rule only matches if the packet wasnot received on the given interface. If a plus mark is appended tothe interface name, the rule is true for any interface that begins withthe name. If the interface name is not specified, packets receivedfrom any interface matches the rule. Only for packets entering theINPUT, FORWARD, and PREROUTING chains.-o Interface on which the packet will be sent. If an exclamation pointand a space is before it, the rule only matches if the packet was notreceived on the given interface. If a plus mark is appended to theinterface name, the rule is true for any interface that begins with thename. If the interface name is not specified, packets to be sentfrom any interface matches the rule. Only for packets entering theINPUT, FORWARD, and PREROUTING chains.-f Rule only matches second and further fragmented packets. If anexclamation point is before the -f parameter, the rule only matchesunfragmented packets.-c PKTS BYTES Used to initialize the packet and byte counters of the rule. Only forINSERT, APPEND, and REPLACE actions.Selecting IPTables OptionsEach rule may contain the options in Table 24.3, but they are not required. They shouldbe listed in the rule after the command and any rule specifications for the command suchas the following:iptables -t -A --line-numbers ...TABLE 24.3 IPTables OptionsIPTables OptionDescription-v Show more details if available such as the interface nameand counters when listing rules.-n Do not resolve IP addresses to hostnames, port numbers toservice names, or network address to network names. Canbe used to speed up output of commands such as listingthe rules.-x Provide the exact values of the packet and byte counters.Only applicable to the -L command.--line-numbersWhen listing rules, display line numbers in front of each ruleto show the position of the rule in the chain.--modprobe= When adding or inserting rules, use the specified commandto load additional kernel modules.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!