<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>iptables archivos - RAGASYS SISTEMAS</title>
	<atom:link href="https://blog.ragasys.es/tag/iptables/feed" rel="self" type="application/rss+xml" />
	<link>https://blog.ragasys.es/tag/iptables</link>
	<description>Soporte técnico para las TIC</description>
	<lastBuildDate>Mon, 29 May 2023 17:32:08 +0000</lastBuildDate>
	<language>es</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2020/05/logoRGS_18_05_2020.png?fit=32%2C32&#038;ssl=1</url>
	<title>iptables archivos - RAGASYS SISTEMAS</title>
	<link>https://blog.ragasys.es/tag/iptables</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">111701399</site>	<item>
		<title>Configuración Firewall con iptables</title>
		<link>https://blog.ragasys.es/configuracion-firewall-con-iptables</link>
					<comments>https://blog.ragasys.es/configuracion-firewall-con-iptables#respond</comments>
		
		<dc:creator><![CDATA[Jose Ramon Ramos Gata]]></dc:creator>
		<pubDate>Mon, 29 May 2023 17:32:08 +0000</pubDate>
				<category><![CDATA[Filtrados]]></category>
		<category><![CDATA[Firewall]]></category>
		<category><![CDATA[iptables]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[netwo]]></category>
		<category><![CDATA[Seguridad]]></category>
		<guid isPermaLink="false">https://blog.ragasys.es/?p=16180</guid>

					<description><![CDATA[<p>Hola a tod@s, en este post vamos a ver ejemplos de como configurar un firewall con iptables, el esquema de la infraestructura montada sería el siguiente: En nuestra infraestructura de virtualización VMware, hemos desplegado estas dos máquinas, una llamada cortafuegos&#8230; <a href="https://blog.ragasys.es/configuracion-firewall-con-iptables" class="more-link">Continuar leyendo <span class="meta-nav">&#8594;</span></a></p>
<p>La entrada <a href="https://blog.ragasys.es/configuracion-firewall-con-iptables">Configuración Firewall con iptables</a> se publicó primero en <a href="https://blog.ragasys.es">RAGASYS SISTEMAS</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Hola a tod@s, en este post vamos a ver ejemplos de como configurar un firewall con iptables, el esquema de la infraestructura montada sería el siguiente:</p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_1.png?ssl=1" data-lbwps-width="747" data-lbwps-height="315" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_1.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16181" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_1#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_1.png?fit=747%2C315&amp;ssl=1" data-orig-size="747,315" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_1" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_1.png?fit=640%2C270&amp;ssl=1" class="aligncenter size-full wp-image-16181" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_1.png?resize=640%2C270&#038;ssl=1" alt="" width="640" height="270" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_1.png?w=747&amp;ssl=1 747w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_1.png?resize=595%2C251&amp;ssl=1 595w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En nuestra infraestructura de virtualización VMware, hemos desplegado estas dos máquinas, una llamada <strong>cortafuegos </strong>y otra <strong>servidor</strong> con las configuraciones de red indicadas en la actividad, la máquina <strong>cortafuegos</strong> es un Ubuntu Server 20.04 sin interfaz gráfica y la máquina <strong>servidor</strong> es un Ubuntu Server 20.04 con interfaz gráfica:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_2.png?ssl=1" data-lbwps-width="1101" data-lbwps-height="758" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_2.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16182" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_2#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_2.png?fit=1101%2C758&amp;ssl=1" data-orig-size="1101,758" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_2" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_2.png?fit=640%2C441&amp;ssl=1" class="aligncenter size-full wp-image-16182" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_2.png?resize=640%2C441&#038;ssl=1" alt="" width="640" height="441" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_2.png?w=1101&amp;ssl=1 1101w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_2.png?resize=595%2C410&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_2.png?resize=960%2C661&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_2.png?resize=768%2C529&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_3.png?ssl=1" data-lbwps-width="1105" data-lbwps-height="764" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_3.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16183" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_3#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_3.png?fit=1105%2C764&amp;ssl=1" data-orig-size="1105,764" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_3" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_3.png?fit=640%2C443&amp;ssl=1" class="aligncenter size-full wp-image-16183" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_3.png?resize=640%2C442&#038;ssl=1" alt="" width="640" height="442" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_3.png?w=1105&amp;ssl=1 1105w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_3.png?resize=595%2C411&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_3.png?resize=960%2C664&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_3.png?resize=768%2C531&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>La configuración de red para la máquina<strong> cortafuegos</strong> es la siguiente, hemos renombrado las interfaces de red para tenerlo todo más claro (WAN y LAN):</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_4.png?ssl=1" data-lbwps-width="806" data-lbwps-height="231" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_4.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16184" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_4#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_4.png?fit=806%2C231&amp;ssl=1" data-orig-size="806,231" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_4" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_4.png?fit=640%2C183&amp;ssl=1" class="aligncenter size-full wp-image-16184" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_4.png?resize=640%2C183&#038;ssl=1" alt="" width="640" height="183" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_4.png?w=806&amp;ssl=1 806w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_4.png?resize=595%2C171&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_4.png?resize=768%2C220&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_5.png?ssl=1" data-lbwps-width="811" data-lbwps-height="484" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_5.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16185" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_5#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_5.png?fit=811%2C484&amp;ssl=1" data-orig-size="811,484" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_5" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_5.png?fit=640%2C382&amp;ssl=1" class="aligncenter size-full wp-image-16185" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_5.png?resize=640%2C382&#038;ssl=1" alt="" width="640" height="382" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_5.png?w=811&amp;ssl=1 811w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_5.png?resize=595%2C355&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_5.png?resize=768%2C458&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_6.png?ssl=1" data-lbwps-width="823" data-lbwps-height="443" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_6.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16186" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_6#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_6.png?fit=823%2C443&amp;ssl=1" data-orig-size="823,443" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_6" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_6.png?fit=640%2C344&amp;ssl=1" class="aligncenter size-full wp-image-16186" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_6.png?resize=640%2C344&#038;ssl=1" alt="" width="640" height="344" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_6.png?w=823&amp;ssl=1 823w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_6.png?resize=595%2C320&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_6.png?resize=768%2C413&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>La configuración de red para la máquina<strong> servidor</strong> es:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_7.png?ssl=1" data-lbwps-width="806" data-lbwps-height="403" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_7.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16187" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_7#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_7.png?fit=806%2C403&amp;ssl=1" data-orig-size="806,403" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_7" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_7.png?fit=640%2C320&amp;ssl=1" class="aligncenter size-full wp-image-16187" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_7.png?resize=640%2C320&#038;ssl=1" alt="" width="640" height="320" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_7.png?w=806&amp;ssl=1 806w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_7.png?resize=595%2C298&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_7.png?resize=768%2C384&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_8.png?ssl=1" data-lbwps-width="808" data-lbwps-height="324" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_8.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16188" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_8#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_8.png?fit=808%2C324&amp;ssl=1" data-orig-size="808,324" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_8" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_8.png?fit=640%2C257&amp;ssl=1" class="aligncenter size-full wp-image-16188" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_8.png?resize=640%2C257&#038;ssl=1" alt="" width="640" height="257" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_8.png?w=808&amp;ssl=1 808w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_8.png?resize=595%2C239&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_8.png?resize=768%2C308&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En la máquina <strong>servidor</strong> podemos ver, que la ruta por defecto, sale a través de la máquina <strong>cortafuegos (10.0.0.1)</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_9.png?ssl=1" data-lbwps-width="817" data-lbwps-height="241" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_9.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16189" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_9#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_9.png?fit=817%2C241&amp;ssl=1" data-orig-size="817,241" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_9" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_9.png?fit=640%2C189&amp;ssl=1" class="aligncenter size-full wp-image-16189" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_9.png?resize=640%2C189&#038;ssl=1" alt="" width="640" height="189" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_9.png?w=817&amp;ssl=1 817w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_9.png?resize=595%2C176&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_9.png?resize=768%2C227&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora vamos a realizar las siguientes tareas con el cortafuegos configurando <strong>iptables.</strong></li>
<li><strong>Preparar el Cortafuegos para que haga NAT compartiendo la IP de la interface WAN:</strong></li>
<li>Lo primero que vamos a realizar es que la máquina <strong>cortafuegos</strong> deje pasar el tráfico entre la red externa (WAN) y la red interna (LAN), para ello, editamos el fichero <strong>/etc/sysctl.conf</strong> y descomentamos la línea <strong>net.ipv4.ip_forward=1:</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_10.png?ssl=1" data-lbwps-width="814" data-lbwps-height="668" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_10.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16190" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_10#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_10.png?fit=814%2C668&amp;ssl=1" data-orig-size="814,668" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_10" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_10.png?fit=640%2C525&amp;ssl=1" class="aligncenter size-full wp-image-16190" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_10.png?resize=640%2C525&#038;ssl=1" alt="" width="640" height="525" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_10.png?w=814&amp;ssl=1 814w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_10.png?resize=595%2C488&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_10.png?resize=768%2C630&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ejecutamos <strong>sysctl -p /etc/sysctl.conf</strong> para que los cambios tengan efecto:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_11.png?ssl=1" data-lbwps-width="811" data-lbwps-height="181" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_11.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16191" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_11#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_11.png?fit=811%2C181&amp;ssl=1" data-orig-size="811,181" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_11" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_11.png?fit=640%2C143&amp;ssl=1" class="aligncenter size-full wp-image-16191" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_11.png?resize=640%2C143&#038;ssl=1" alt="" width="640" height="143" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_11.png?w=811&amp;ssl=1 811w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_11.png?resize=595%2C133&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_11.png?resize=768%2C171&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En la máquina <strong>cortafuegos </strong>configuramos la siguiente regla, para que haga NAT compartiendo la IP dinámica de la interface WAN <strong>iptables -t nat -A POSTROUTING -o WAN -j MASQUERADE:</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_12.png?ssl=1" data-lbwps-width="805" data-lbwps-height="185" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_12.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16192" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_12#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_12.png?fit=805%2C185&amp;ssl=1" data-orig-size="805,185" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_12" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_12.png?fit=640%2C147&amp;ssl=1" class="aligncenter size-full wp-image-16192" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_12.png?resize=640%2C147&#038;ssl=1" alt="" width="640" height="147" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_12.png?w=805&amp;ssl=1 805w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_12.png?resize=595%2C137&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_12.png?resize=768%2C176&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Una vez configurada la máquina <strong>cortafuegos</strong>, vamos a realizar la prueba desde la máquina <strong>servidor</strong>, y verificar que podemos navegar hacia suarezdefigueroa.es:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_13.png?ssl=1" data-lbwps-width="813" data-lbwps-height="672" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_13.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16193" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_13#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_13.png?fit=813%2C672&amp;ssl=1" data-orig-size="813,672" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_13" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_13.png?fit=640%2C529&amp;ssl=1" class="aligncenter size-full wp-image-16193" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_13.png?resize=640%2C529&#038;ssl=1" alt="" width="640" height="529" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_13.png?w=813&amp;ssl=1 813w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_13.png?resize=595%2C492&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_13.png?resize=768%2C635&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para finalizar, guardamos la configuración, para que al reiniciar el sistema se carguen las iptables que hemos diseñado:</li>
</ul>
<p><strong>apt-get install iptables-persistent</strong></p>
<p><strong>iptables-save &gt; /etc/iptables/rules.v4</strong></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_14.png?ssl=1" data-lbwps-width="806" data-lbwps-height="285" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_14.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16194" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_14#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_14.png?fit=806%2C285&amp;ssl=1" data-orig-size="806,285" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_14" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_14.png?fit=640%2C226&amp;ssl=1" class="aligncenter size-full wp-image-16194" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_14.png?resize=640%2C226&#038;ssl=1" alt="" width="640" height="226" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_14.png?w=806&amp;ssl=1 806w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_14.png?resize=595%2C210&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_14.png?resize=768%2C272&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_15.png?ssl=1" data-lbwps-width="809" data-lbwps-height="158" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_15.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16195" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_15#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_15.png?fit=809%2C158&amp;ssl=1" data-orig-size="809,158" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_15" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_15.png?fit=640%2C125&amp;ssl=1" class="aligncenter size-full wp-image-16195" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_15.png?resize=640%2C125&#038;ssl=1" alt="" width="640" height="125" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_15.png?w=809&amp;ssl=1 809w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_15.png?resize=595%2C116&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_15.png?resize=768%2C150&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li><strong>Abrir los puertos 80 (instalar apache en Servidor) y 21 (instalar vsftpd en Servidor) hacia el servidor:</strong></li>
<li>Sobre la máquina <strong>servidor</strong> instalamos el servidor web apache:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_16.png?ssl=1" data-lbwps-width="808" data-lbwps-height="399" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_16.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16196" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_16#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_16.png?fit=808%2C399&amp;ssl=1" data-orig-size="808,399" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_16" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_16.png?fit=640%2C316&amp;ssl=1" class="aligncenter size-full wp-image-16196" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_16.png?resize=640%2C316&#038;ssl=1" alt="" width="640" height="316" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_16.png?w=808&amp;ssl=1 808w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_16.png?resize=595%2C294&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_16.png?resize=768%2C379&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Sobre la máquina <strong>servidor</strong> instalamos el servidor FTP vsftpd:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_17.png?ssl=1" data-lbwps-width="809" data-lbwps-height="495" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_17.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16197" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_17#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_17.png?fit=809%2C495&amp;ssl=1" data-orig-size="809,495" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_17" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_17.png?fit=640%2C392&amp;ssl=1" class="aligncenter size-full wp-image-16197" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_17.png?resize=640%2C392&#038;ssl=1" alt="" width="640" height="392" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_17.png?w=809&amp;ssl=1 809w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_17.png?resize=595%2C364&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_17.png?resize=768%2C470&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora en la máquina <strong>cortafuegos</strong> vamos a configurar la regla con iptables para abrir el puerto 80 hacia el <strong>servidor</strong>, para ello, introducimos <strong>iptables -t nat -A PREROUTING -p tcp &#8211;dport 80 -i WAN -j DNAT &#8211;to 10.0.0.10:80</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_18.png?ssl=1" data-lbwps-width="811" data-lbwps-height="187" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_18.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16198" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_18#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_18.png?fit=811%2C187&amp;ssl=1" data-orig-size="811,187" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_18" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_18.png?fit=640%2C148&amp;ssl=1" class="aligncenter size-full wp-image-16198" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_18.png?resize=640%2C148&#038;ssl=1" alt="" width="640" height="148" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_18.png?w=811&amp;ssl=1 811w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_18.png?resize=595%2C137&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_18.png?resize=768%2C177&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>En la máquina <strong>cortafuegos</strong> vamos a configurar la regla con iptables para abrir el puerto 21 hacia el <strong>servidor</strong>, para ello, introducimos <strong>iptables -t nat -A PREROUTING -p tcp &#8211;dport 21 -i WAN -j DNAT &#8211;to 10.0.0.10:21:</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_19.png?ssl=1" data-lbwps-width="813" data-lbwps-height="180" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_19.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16199" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_19#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_19.png?fit=813%2C180&amp;ssl=1" data-orig-size="813,180" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_19" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_19.png?fit=640%2C142&amp;ssl=1" class="aligncenter size-full wp-image-16199" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_19.png?resize=640%2C142&#038;ssl=1" alt="" width="640" height="142" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_19.png?w=813&amp;ssl=1 813w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_19.png?resize=595%2C132&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_19.png?resize=768%2C170&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para finalizar, guardamos la configuración, para que al reiniciar el sistema se carguen las iptables que hemos diseñado:</li>
</ul>
<p><strong>iptables-save &gt; /etc/iptables/rules.v4</strong></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_20.png?ssl=1" data-lbwps-width="809" data-lbwps-height="157" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_20.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16200" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_20#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_20.png?fit=809%2C157&amp;ssl=1" data-orig-size="809,157" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_20" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_20.png?fit=640%2C124&amp;ssl=1" class="aligncenter size-full wp-image-16200" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_20.png?resize=640%2C124&#038;ssl=1" alt="" width="640" height="124" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_20.png?w=809&amp;ssl=1 809w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_20.png?resize=595%2C115&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_20.png?resize=768%2C149&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora que hemos configurado las reglas con iptables, nos vamos a conectar al puerto 80 de la interface WAN de la máquina <strong>cortafuegos</strong> (192.168.14.101, ip servida por DHCP al cortafuegos) y como podemos ver, nos dirige al apache instalado en la máquina <strong>servidor</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_21.png?ssl=1" data-lbwps-width="1359" data-lbwps-height="1049" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_21.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16201" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_21#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_21.png?fit=1359%2C1049&amp;ssl=1" data-orig-size="1359,1049" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_21" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_21.png?fit=640%2C494&amp;ssl=1" class="aligncenter size-full wp-image-16201" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_21.png?resize=640%2C494&#038;ssl=1" alt="" width="640" height="494" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_21.png?w=1359&amp;ssl=1 1359w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_21.png?resize=595%2C459&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_21.png?resize=960%2C741&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_21.png?resize=768%2C593&amp;ssl=1 768w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_21.png?w=1280&amp;ssl=1 1280w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Nos conectamos ahora al puerto 21 de la interface WAN de la máquina <strong>cortafuegos</strong> (192.168.14.101, ip servida por DHCP al cortafuegos) y como podemos ver, nos dirige al FTP instalado en la máquina <strong>servidor</strong>:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_22.png?ssl=1" data-lbwps-width="1146" data-lbwps-height="530" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_22.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16202" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_22#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_22.png?fit=1146%2C530&amp;ssl=1" data-orig-size="1146,530" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_22" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_22.png?fit=640%2C296&amp;ssl=1" class="aligncenter size-full wp-image-16202" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_22.png?resize=640%2C296&#038;ssl=1" alt="" width="640" height="296" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_22.png?w=1146&amp;ssl=1 1146w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_22.png?resize=595%2C275&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_22.png?resize=960%2C444&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_22.png?resize=768%2C355&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_23.png?ssl=1" data-lbwps-width="994" data-lbwps-height="332" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_23.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16203" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_23#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_23.png?fit=994%2C332&amp;ssl=1" data-orig-size="994,332" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_23" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_23.png?fit=640%2C214&amp;ssl=1" class="aligncenter size-full wp-image-16203" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_23.png?resize=640%2C214&#038;ssl=1" alt="" width="640" height="214" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_23.png?w=994&amp;ssl=1 994w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_23.png?resize=595%2C199&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_23.png?resize=960%2C321&amp;ssl=1 960w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_23.png?resize=768%2C257&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li><strong>Permitir el acceso por SSH al cortafuegos cuando NO provenga de la MAC 02:42:02:42:02:42</strong></li>
<li>En Ubuntu Server 20.04 LTS que es el sistema operativo de la máquina <strong>cortafuegos</strong> viene instalado por defecto openssh-server, como podemos ver aquí, accedemos sin problemas por SSH:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_24.png?ssl=1" data-lbwps-width="658" data-lbwps-height="676" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_24.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16204" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_24#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_24.png?fit=658%2C676&amp;ssl=1" data-orig-size="658,676" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_24" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_24.png?fit=640%2C658&amp;ssl=1" class="aligncenter size-full wp-image-16204" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_24.png?resize=640%2C658&#038;ssl=1" alt="" width="640" height="658" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_24.png?w=658&amp;ssl=1 658w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_24.png?resize=595%2C611&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_24.png?resize=50%2C50&amp;ssl=1 50w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Ahora en la máquina <strong>cortafuegos</strong> vamos a configurar la regla con iptables para no permitir el acceso por SSH cuando provenga de la MAC 02:42:02:42:02:42, para ello, introducimos <strong>iptables -A FORWARD -m mac &#8211;mac-source 02:42:02:42:02:42 -p tcp &#8211;dport 22 -j DROP</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_25.png?ssl=1" data-lbwps-width="821" data-lbwps-height="213" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_25.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16205" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_25#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_25.png?fit=821%2C213&amp;ssl=1" data-orig-size="821,213" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_25" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_25.png?fit=640%2C166&amp;ssl=1" class="aligncenter size-full wp-image-16205" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_25.png?resize=640%2C166&#038;ssl=1" alt="" width="640" height="166" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_25.png?w=821&amp;ssl=1 821w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_25.png?resize=595%2C154&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_25.png?resize=768%2C199&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para finalizar, guardamos la configuración, para que al reiniciar el sistema se carguen las iptables que hemos diseñado:</li>
</ul>
<p><strong>iptables-save &gt; /etc/iptables/rules.v4</strong></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_26.png?ssl=1" data-lbwps-width="809" data-lbwps-height="157" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_26.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16206" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_26#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_26.png?fit=809%2C157&amp;ssl=1" data-orig-size="809,157" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_26" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_26.png?fit=640%2C124&amp;ssl=1" class="aligncenter size-full wp-image-16206" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_26.png?resize=640%2C124&#038;ssl=1" alt="" width="640" height="124" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_26.png?w=809&amp;ssl=1 809w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_26.png?resize=595%2C115&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_26.png?resize=768%2C149&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li><strong>Bloquear el acceso desde el Servidor a la web suarezdefigueroa.es</strong></li>
<li>En la máquina <strong>cortafuegos</strong> vamos a configurar la regla con iptables para bloquear el acceso desde el servidor a la web suarezdefigueroa.es, para ello, introducimos<strong> iptables -t filter -A FORWARD -s 10.0.0.10 -d www.suarezdefigueroa.es -j DROP</strong></li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_27.png?ssl=1" data-lbwps-width="806" data-lbwps-height="154" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_27.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16207" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_27#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_27.png?fit=806%2C154&amp;ssl=1" data-orig-size="806,154" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_27" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_27.png?fit=640%2C122&amp;ssl=1" class="aligncenter size-full wp-image-16207" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_27.png?resize=640%2C122&#038;ssl=1" alt="" width="640" height="122" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_27.png?w=806&amp;ssl=1 806w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_27.png?resize=595%2C114&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_27.png?resize=768%2C147&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para finalizar, guardamos la configuración, para que al reiniciar el sistema se carguen las iptables que hemos diseñado:</li>
</ul>
<p><strong>iptables-save &gt; /etc/iptables/rules.v4</strong></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_28.png?ssl=1" data-lbwps-width="809" data-lbwps-height="157" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_28.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16208" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_28#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_28.png?fit=809%2C157&amp;ssl=1" data-orig-size="809,157" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_28" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_28.png?fit=640%2C124&amp;ssl=1" class="aligncenter size-full wp-image-16208" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_28.png?resize=640%2C124&#038;ssl=1" alt="" width="640" height="124" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_28.png?w=809&amp;ssl=1 809w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_28.png?resize=595%2C115&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_28.png?resize=768%2C149&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Desde la máquina servidor, podemos ver, que ya no se puede acceder a la web suarezdefigueroa.es:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_29.png?ssl=1" data-lbwps-width="813" data-lbwps-height="675" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_29.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16209" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_29#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_29.png?fit=813%2C675&amp;ssl=1" data-orig-size="813,675" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_29" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_29.png?fit=640%2C531&amp;ssl=1" class="aligncenter size-full wp-image-16209" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_29.png?resize=640%2C531&#038;ssl=1" alt="" width="640" height="531" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_29.png?w=813&amp;ssl=1 813w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_29.png?resize=595%2C494&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_29.png?resize=768%2C638&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li><strong>No permitir el ping con origen externo hacia el Servidor</strong></li>
<li>En la máquina <strong>cortafuegos</strong> vamos a configurar la regla con iptables para no permitir el ping con origen externo hacia el <strong>servidor</strong>, para ello, introducimos <strong>iptables -t filter -A OUTPUT -d 10.0.0.10 -p icmp -j DROP</strong>, luego le realizamos un ping desde la propia máquina <strong>cortafuegos</strong> al <strong>servidor</strong> y como vemos, la operación no está permitida:</li>
</ul>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_30.png?ssl=1" data-lbwps-width="808" data-lbwps-height="322" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_30.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16210" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_30#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_30.png?fit=808%2C322&amp;ssl=1" data-orig-size="808,322" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_30" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_30.png?fit=640%2C255&amp;ssl=1" class="aligncenter size-full wp-image-16210" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_30.png?resize=640%2C255&#038;ssl=1" alt="" width="640" height="255" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_30.png?w=808&amp;ssl=1 808w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_30.png?resize=595%2C237&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_30.png?resize=768%2C306&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<ul>
<li>Para finalizar, guardamos la configuración, para que al reiniciar el sistema se carguen las iptables que hemos diseñado:</li>
</ul>
<p><strong>iptables-save &gt; /etc/iptables/rules.v4</strong></p>
<p><a href="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_31.png?ssl=1" data-lbwps-width="809" data-lbwps-height="157" data-lbwps-srcsmall="https://blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_31.png"><img data-recalc-dims="1" loading="lazy" decoding="async" data-attachment-id="16211" data-permalink="https://blog.ragasys.es/configuracion-firewall-con-iptables/cfciptables_31#main" data-orig-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_31.png?fit=809%2C157&amp;ssl=1" data-orig-size="809,157" data-comments-opened="1" data-image-meta="{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}" data-image-title="cfciptables_31" data-image-description="" data-image-caption="" data-large-file="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_31.png?fit=640%2C124&amp;ssl=1" class="aligncenter size-full wp-image-16211" src="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_31.png?resize=640%2C124&#038;ssl=1" alt="" width="640" height="124" srcset="https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_31.png?w=809&amp;ssl=1 809w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_31.png?resize=595%2C115&amp;ssl=1 595w, https://i0.wp.com/blog.ragasys.es/wp-content/uploads/2023/01/cfciptables_31.png?resize=768%2C149&amp;ssl=1 768w" sizes="auto, (max-width: 640px) 100vw, 640px" /></a></p>
<p>&nbsp;</p>
<p>Saludos y espero que os resulte de ayuda <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>
<p><strong> </strong></p>
<p><strong> </strong></p>
<p>&nbsp;</p>
<p>La entrada <a href="https://blog.ragasys.es/configuracion-firewall-con-iptables">Configuración Firewall con iptables</a> se publicó primero en <a href="https://blog.ragasys.es">RAGASYS SISTEMAS</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.ragasys.es/configuracion-firewall-con-iptables/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">16180</post-id>	</item>
	</channel>
</rss>
