<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>nftables archivos - RAGASYS SISTEMAS</title>
	<atom:link href="https://blog.ragasys.es/category/nftables/feed" rel="self" type="application/rss+xml" />
	<link>https://blog.ragasys.es/category/nftables</link>
	<description>Soporte técnico para las TIC</description>
	<lastBuildDate>Mon, 05 Jun 2023 16:25:17 +0000</lastBuildDate>
	<language>es</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/05/logoRGS_18_05_2020.png?fit=32%2C32&#038;ssl=1</url>
	<title>nftables archivos - RAGASYS SISTEMAS</title>
	<link>https://blog.ragasys.es/category/nftables</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">111701399</site>	<item>
		<title>Configuración Firewall con nftables</title>
		<link>https://blog.ragasys.es/configuracion-firewall-con-nftables</link>
					<comments>https://blog.ragasys.es/configuracion-firewall-con-nftables#respond</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Mon, 05 Jun 2023 16:25:17 +0000</pubDate>
				<category><![CDATA[Filtrados]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[nftables]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=16214</guid>

					<description><![CDATA[<p>Hola a tod@s, en este post vamos a ver ejemplos de como configurar un firewall con nftables, el esquema de la infraestructura montada sería el siguiente: Antes de empezar debemos de ejecutar sobre la máquina cortafuegos los siguientes comandos: apt-get&#8230; <a href="https://blog.ragasys.es/configuracion-firewall-con-nftables" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a></p>
<p>La entrada <a href="https://blog.ragasys.es/configuracion-firewall-con-nftables">Configuración Firewall con nftables</a> se publicó primero en <a href="https://blog.ragasys.es">RAGASYS SISTEMAS</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s, en este post vamos a ver ejemplos de como configurar un firewall con nftables, el esquema de la infraestructura montada sería el siguiente:</p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_1.png?ssl=1" data-lbwps-width="747" data-lbwps-height="315" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_1.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16215" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-nftables/cfcnftables_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_1.png?fit=747%2C315&amp;ssl=1" data-orig-size="747,315" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfcnftables_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_1.png?fit=640%2C270&amp;ssl=1" class="aligncenter size-full wp-image-16215" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_1.png?resize=640%2C270&#038;ssl=1" alt="" width="640" height="270" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_1.png?w=747&amp;ssl=1 747w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_1.png?resize=595%2C251&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>Antes de empezar debemos de ejecutar sobre la máquina cortafuegos los siguientes comandos:</p>
<p><strong>apt-get update</strong> para actualizar</p>
<p><strong>apt-get install nftables </strong>para instalar</p>
<p><strong>systemctl start nftables.service </strong>para iniciar el servicio</p>
<p><strong>systemctl status nftables.service </strong>para ver el estado del servicio</p>
<ul>
<li>Vamos a crear una tabla llamada accesojramos, en la máquina <strong>cortafuegos</strong> vamos a añadir la tabla indicando, <strong>nft add table inet accesojramos</strong> con <strong>nft list tables</strong> podemos ver el listado de tablas:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_2.png?ssl=1" data-lbwps-width="810" data-lbwps-height="205" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_2.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16216" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-nftables/cfcnftables_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_2.png?fit=810%2C205&amp;ssl=1" data-orig-size="810,205" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfcnftables_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_2.png?fit=640%2C162&amp;ssl=1" class="aligncenter size-full wp-image-16216" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_2.png?resize=640%2C162&#038;ssl=1" alt="" width="640" height="162" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_2.png?w=810&amp;ssl=1 810w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_2.png?resize=595%2C151&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_2.png?resize=768%2C194&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Vamos a crear dos cadenas en los hook input y output con política accept por defecto</li>
<li>En la máquina <strong>cortafuegos</strong> vamos a añadir las dos cadenas en los hook input y output con política accept por defecto, para ello, introducimos para la entrada <strong>nft add chain inet accesojramos entrada { type filter hook input priority 0 \; policy accept \;}</strong> y para la salida <strong>nft add chain inet accesojramos salida { type filter hook output priority 0 \; policy accept \;}</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_3.png?ssl=1" data-lbwps-width="835" data-lbwps-height="281" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_3.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16217" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-nftables/cfcnftables_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_3.png?fit=835%2C281&amp;ssl=1" data-orig-size="835,281" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfcnftables_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_3.png?fit=640%2C215&amp;ssl=1" class="aligncenter size-full wp-image-16217" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_3.png?resize=640%2C215&#038;ssl=1" alt="" width="640" height="215" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_3.png?w=835&amp;ssl=1 835w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_3.png?resize=595%2C200&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_3.png?resize=768%2C258&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Con <strong>nft list table inet accesojramos</strong> podemos ver la tabla con su contenido:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_4.png?ssl=1" data-lbwps-width="817" data-lbwps-height="315" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_4.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16218" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-nftables/cfcnftables_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_4.png?fit=817%2C315&amp;ssl=1" data-orig-size="817,315" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfcnftables_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_4.png?fit=640%2C247&amp;ssl=1" class="aligncenter size-full wp-image-16218" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_4.png?resize=640%2C247&#038;ssl=1" alt="" width="640" height="247" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_4.png?w=817&amp;ssl=1 817w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_4.png?resize=595%2C229&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_4.png?resize=768%2C296&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para finalizar, guardamos la configuración y reiniciamos el servicio, <strong>nft list ruleset &gt; /etc/nftables.conf</strong> y <strong>systemctl restart nftables.service</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_5.png?ssl=1" data-lbwps-width="804" data-lbwps-height="147" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_5.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16219" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-nftables/cfcnftables_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_5.png?fit=804%2C147&amp;ssl=1" data-orig-size="804,147" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfcnftables_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_5.png?fit=640%2C117&amp;ssl=1" class="aligncenter size-full wp-image-16219" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_5.png?resize=640%2C117&#038;ssl=1" alt="" width="640" height="117" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_5.png?w=804&amp;ssl=1 804w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_5.png?resize=595%2C109&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_5.png?resize=768%2C140&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Bloquear en la entrada el acceso al servidor FTP desde el Cortafuegos</li>
<li>En la máquina cortafuegos introducimos, <strong>nft add rule inet accesojramos entrada ip daddr 10.0.0.10 tcp dport 21 counter reject</strong> y con <strong>nft list table inet accesojramos</strong> podemos ver la tabla con su contenido:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_6.png?ssl=1" data-lbwps-width="843" data-lbwps-height="355" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_6.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16220" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-nftables/cfcnftables_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_6.png?fit=843%2C355&amp;ssl=1" data-orig-size="843,355" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfcnftables_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_6.png?fit=640%2C270&amp;ssl=1" class="aligncenter size-full wp-image-16220" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_6.png?resize=640%2C270&#038;ssl=1" alt="" width="640" height="270" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_6.png?w=843&amp;ssl=1 843w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_6.png?resize=595%2C251&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_6.png?resize=768%2C323&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para finalizar, guardamos la configuración y reiniciamos el servicio, <strong>nft list ruleset &gt; /etc/nftables.conf</strong> y <strong>systemctl restart nftables.service</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_5.png?ssl=1" data-lbwps-width="804" data-lbwps-height="147" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_5.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16219" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-nftables/cfcnftables_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_5.png?fit=804%2C147&amp;ssl=1" data-orig-size="804,147" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfcnftables_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_5.png?fit=640%2C117&amp;ssl=1" class="aligncenter size-full wp-image-16219" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_5.png?resize=640%2C117&#038;ssl=1" alt="" width="640" height="117" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_5.png?w=804&amp;ssl=1 804w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_5.png?resize=595%2C109&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_5.png?resize=768%2C140&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Bloquear en la salida el ping con cualquier IP destino u origen</li>
<li>En la máquina cortafuegos introducimos, <strong>nft add rule inet accesojramos salida ip protocol icmp drop</strong> y con <strong>nft list table inet accesojramos</strong> podemos ver la tabla con su contenido:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_8.png?ssl=1" data-lbwps-width="811" data-lbwps-height="464" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_8.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16222" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-nftables/cfcnftables_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_8.png?fit=811%2C464&amp;ssl=1" data-orig-size="811,464" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfcnftables_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_8.png?fit=640%2C366&amp;ssl=1" class="aligncenter size-full wp-image-16222" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_8.png?resize=640%2C366&#038;ssl=1" alt="" width="640" height="366" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_8.png?w=811&amp;ssl=1 811w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_8.png?resize=595%2C340&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_8.png?resize=768%2C439&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para finalizar, guardamos la configuración y reiniciamos el servicio, <strong>nft list ruleset &gt; /etc/nftables.conf</strong> y <strong>systemctl restart nftables.service</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_9.png?ssl=1" data-lbwps-width="804" data-lbwps-height="147" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_9.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16223" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-nftables/cfcnftables_9#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_9.png?fit=804%2C147&amp;ssl=1" data-orig-size="804,147" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfcnftables_9" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_9.png?fit=640%2C117&amp;ssl=1" class="aligncenter size-full wp-image-16223" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_9.png?resize=640%2C117&#038;ssl=1" alt="" width="640" height="117" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_9.png?w=804&amp;ssl=1 804w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_9.png?resize=595%2C109&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_9.png?resize=768%2C140&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora si desde la máquina <strong>servidor</strong> intentamos hacer un ping a la máquina <strong>cortafuegos</strong>, podemos ver que no funciona:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_10.png?ssl=1" data-lbwps-width="822" data-lbwps-height="223" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_10.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16224" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-nftables/cfcnftables_10#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_10.png?fit=822%2C223&amp;ssl=1" data-orig-size="822,223" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfcnftables_10" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_10.png?fit=640%2C174&amp;ssl=1" class="aligncenter size-full wp-image-16224" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_10.png?resize=640%2C174&#038;ssl=1" alt="" width="640" height="174" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_10.png?w=822&amp;ssl=1 822w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_10.png?resize=595%2C161&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_10.png?resize=768%2C208&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Mostramos toda la configuración indicando el código de cada línea</li>
<li>Con <strong>nft list table inet accesojramos</strong> podemos ver toda la configuración realizada y el código de cada línea:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_11.png?ssl=1" data-lbwps-width="815" data-lbwps-height="340" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_11.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16225" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-nftables/cfcnftables_11#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_11.png?fit=815%2C340&amp;ssl=1" data-orig-size="815,340" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfcnftables_11" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_11.png?fit=640%2C267&amp;ssl=1" class="aligncenter size-full wp-image-16225" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_11.png?resize=640%2C267&#038;ssl=1" alt="" width="640" height="267" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_11.png?w=815&amp;ssl=1 815w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_11.png?resize=595%2C248&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfcnftables_11.png?resize=768%2C320&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>Saludos y espero que os sea de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p>&nbsp;</p>
<p>La entrada <a href="https://blog.ragasys.es/configuracion-firewall-con-nftables">Configuración Firewall con nftables</a> se publicó primero en <a href="https://blog.ragasys.es">RAGASYS SISTEMAS</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/configuracion-firewall-con-nftables/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">16214</post-id>	</item>
	</channel>
</rss>
