Lab 10

Updated 4 Oct 2026

🔥 Lab 10 — Basic Linux Firewall · Cheat Sheet

ITS352/DES352 · SIIT · Thammasat University


1 · Firewall Concepts

A firewall sits between the internal network and the Internet — it forwards some packets and filters (drops) others based on rules in a filter table.

Three Chains

ChainHandles packets that are…Analogy
INPUTDestined for THIS machineMail addressed to the post office itself
FORWARDPassing THROUGH this machine to another hostMail passing through the post office
OUTPUTOriginating FROM this machineMail sent out by the post office
[Incoming packet]
      ↓
  Is it FOR this machine?
  ├── YES → INPUT chain → Local Process → OUTPUT chain → [out]
  └── NO  → FORWARD chain → [out to next hop]

Filter Table Criteria

Rules can match on: source/destination IP, source/destination port, protocol (tcp/udp/icmp), network interface

Rule Checking Order ⚠️

  • Rules checked top to bottom, one by one
  • First matching rule wins — remaining rules are skipped
  • If no rule matches → DEFAULT RULE (policy) is applied ← quiz answer

2 · Firewall Strategies

StrategyDefault PolicyAdd rules to…Security
BlacklistingACCEPTDROP bad packetsLower
WhitelistingDROPACCEPT good packetsHigher ✅

Blacklisting = "let everyone in except the banned list"
Whitelisting = "only let approved people in — everyone else out" ← more secure, more popular

Quiz trap: To protect an internal network → INPUT = Whitelisting (DROP default), OUTPUT = Blacklisting(ACCEPT default)


3 · iptables Command Reference

Basic Commands

sudo iptables -nvL                    # View filter table (numeric, verbose, list all)
sudo iptables -F                      # Flush (delete) ALL rules in ALL chains
sudo iptables -F INPUT                # Flush only INPUT chain rules
sudo iptables -F OUTPUT               # Flush only OUTPUT chain rules
sudo iptables -F FORWARD              # Flush only FORWARD chain rules
sudo iptables-save > rules.txt        # Save rules to file
sudo iptables-restore < rules.txt     # Restore rules from file

-nvL output example:

Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target  prot opt in  out  source        destination
    0     0 DROP    icmp --  *   *    192.168.198.0/24  0.0.0.0/0
    0     0 DROP    tcp  --  *   *    35.197.141.103    0.0.0.0/0

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target  prot opt in  out  source    destination

Chain OUTPUT (policy DROP 0 packets, 0 bytes)
 pkts bytes target  prot opt in  out  source    destination
    0     0 ACCEPT  icmp --  *   *    0.0.0.0/0  0.0.0.0/0
    0     0 ACCEPT  tcp  --  *   *    0.0.0.0/0  203.131.209.93

Set Default Policy

sudo iptables -P INPUT ACCEPT         # Default: accept all incoming
sudo iptables -P INPUT DROP           # Default: drop all incoming
sudo iptables -P OUTPUT ACCEPT        # Default: accept all outgoing
sudo iptables -P OUTPUT DROP          # Default: drop all outgoing
sudo iptables -P FORWARD ACCEPT       # Default: accept all forwarded
sudo iptables -P FORWARD DROP         # Default: drop all forwarded

Add / Insert / Delete Rules

Syntax:

sudo iptables <chain-action> <CHAIN> [rule options] -j <ACCEPT|DROP>
FlagAction on chain
-A CHAINAppend rule at the END
-I CHAIN NInsert rule at position N
-I CHAINInsert at the BEGINNING (position 1)
-D CHAIN NDelete rule number N
-P CHAINSet default policy

Rule Options

FlagMatches…Example
-s <ip/subnet>Source IP or network-s 192.168.1.0/24
-d <ip/subnet>Destination IP or network-d 203.131.209.93
-p <proto>Protocol-p tcp / -p udp / -p icmp
--sport <port>Source port--sport 80
--dport <port>Destination port--dport 22
-i <NIC>Incoming interface-i eth0
-o <NIC>Outgoing interface-o eth1
Action flagEffect
-j ACCEPTAccept the packet
-j DROPSilently discard the packet

4 · Command Examples with Expected Output

Allow incoming ping (ICMP) — quiz answer

sudo iptables -A INPUT -p icmp -j ACCEPT

Allow incoming HTTP from a subnet

# Quiz answer format: allow HTTP from 192.168.200.0/24
sudo iptables -A INPUT -p tcp -s 192.168.200.0/24 --dport 80 -j ACCEPT
 
# Shorter accepted form (quiz showed):
sudo iptables -A INPUT -p tcp -s 192.168.200.0/24 -j ACCEPT

Block a website by domain name (OUTPUT)

# Block www.minecraftskins.com (TCP) — quiz answer
sudo iptables -A OUTPUT -p tcp -d www.minecraftskins.com -j DROP
 
# Block www.pantip.com
sudo iptables -A OUTPUT -p tcp -d www.pantip.com -j DROP
# → system auto-resolves domain to IPs, creates multiple DROP rules

Reproduce the quiz's iptables -nvL output (3-point question)

Chain OUTPUT (policy DROP)
  ACCEPT  icmp  0.0.0.0/0  →  0.0.0.0/0
  ACCEPT  tcp   0.0.0.0/0  →  203.131.209.93

Commands to produce this:

# 1. Set default DROP for OUTPUT (whitelisting)
sudo iptables -P OUTPUT DROP
 
# 2. Accept all outgoing ICMP
sudo iptables -A OUTPUT -p icmp -j ACCEPT
 
# 3. Accept TCP to specific IP (203.131.209.93)
sudo iptables -A OUTPUT -p tcp -d 203.131.209.93 -j ACCEPT

5 · Assignment Quick Reference

Assignment 1 — INPUT Blacklisting

sudo iptables -F INPUT
sudo iptables -P INPUT ACCEPT                              # default ACCEPT
sudo iptables -A INPUT -p icmp -s 192.168.198.0/24 -j DROP  # rule 1: drop ICMP from subnet
sudo iptables -A INPUT -p tcp -s 35.197.141.103 -j DROP    # rule 2: drop TCP from SIIT server
sudo iptables -nvL

Expected tests: friend's ping → FAIL ✅ | www.siit.tu.ac.th → not load ✅ | www.tu.ac.th → loads ✅

Assignment 2 — INPUT Whitelisting

sudo iptables -F INPUT
sudo iptables -A INPUT -p icmp -s 192.168.198.0/24 -j ACCEPT  # rule 1: accept ICMP from subnet
sudo iptables -P INPUT DROP                                     # default DROP
sudo iptables -nvL

Expected tests: friend's ping → SUCCEED ✅ | www.tu.ac.th → not load ✅ (HTTP blocked by default DROP)

Assignment 3 — OUTPUT Blacklisting

sudo iptables -F OUTPUT
sudo iptables -P OUTPUT ACCEPT                         # default ACCEPT
sudo iptables -A OUTPUT -p icmp -j DROP                # rule 1: drop all outgoing ICMP
sudo iptables -A OUTPUT -p tcp -d www.pantip.com -j DROP  # rule 2: drop TCP to pantip
sudo iptables -nvL

Expected tests: ping friend → FAIL ✅ | pantip.com → not load ✅ | www.tu.ac.th → loads ✅

Assignment 4 — FORWARD Whitelisting (IMUNES)

# Router R1 (no sudo needed in IMUNES)
sysctl -w net.ipv4.ip_forward=1
iptables -F FORWARD
iptables -A FORWARD -p udp -s 192.168.5.0/24 -j ACCEPT   # rule 1: accept UDP from Net A
iptables -A FORWARD -p icmp -j ACCEPT                      # rule 2: accept all ICMP
iptables -P FORWARD DROP                                    # default DROP
iptables -nvL
TestResult
A ping B✅ ICMP — matches rule 2
B ping A✅ ICMP — matches rule 2
A UDP → B✅ from Net A — matches rule 1
B UDP → A❌ B is not in Net A — hits default DROP
A TCP → B❌ TCP not in rules — hits default DROP

6 · Packet Flow — Which Chain is Used?

Packet scenarioChain used on the router/firewall
Packet arrives, addressed to this machineINPUT
Packet arrives, going to another machineFORWARD
Packet sent by this machineOUTPUT
Router forwarding a packet between networksFORWARD (NOT OUTPUT)

⚠️ KEY: A packet passing through a router uses FORWARD, not OUTPUT.
OUTPUT only applies to packets the router itself generates.


7 · Quiz Question Patterns

QuestionAnswer
Delete all existing firewall rules?sudo iptables -F
Allow incoming ping (ICMP)?sudo iptables -A INPUT -p icmp -j ACCEPT
Blocks all except known source = ? strategyWhitelisting
No rule matches → firewall performs?DEFAULT RULE (policy)
Command to set default for a chain?sudo iptables -P <CHAIN> <ACCEPT|DROP>
Allow HTTP from 192.168.200.0/24?sudo iptables -A INPUT -p tcp -s 192.168.200.0/24 -j ACCEPT
Block website www.minecraftskins.com (TCP)?sudo iptables -A OUTPUT -p tcp -d www.minecraftskins.com -j DROP
Protect internal network: INPUT and OUTPUT strategy?INPUT=Whitelisting, OUTPUT=Blacklisting
Which is more secure: black or white?Whitelisting
What does -A do?Appends rule at the END of chain
What does -I INPUT 1 do?Inserts rule at BEGINNING (position 1)
What does -F do?Flushes (deletes) ALL rules
What does -P do?Sets the DEFAULT POLICY of a chain
-s flag means?Source IP/network
-d flag means?Destination IP/network
-p icmp matches?Ping packets (ICMP protocol)
--dport 80 means?Destination port 80 (HTTP)

3-point Long Answer: Write commands to produce a given iptables -nvL output

Strategy: Read the output → identify default policy → identify each rule in order

OUTPUT (policy DROP)  → sudo iptables -P OUTPUT DROP          # set default first
  ACCEPT icmp any→any → sudo iptables -A OUTPUT -p icmp -j ACCEPT
  ACCEPT tcp  any→IP  → sudo iptables -A OUTPUT -p tcp -d <IP> -j ACCEPT

Explanation: Why whitelisting is more secure

Whitelisting sets the default to DROP, so any unknown or new attack traffic is automatically blocked. You only allow what you explicitly trust. Blacklisting defaults to ACCEPT, so new threats can get through until you add a specific block rule — you can never know all the bad ones in advance.

Explanation: Difference between INPUT and FORWARD

INPUT handles packets addressed to this machine itself (e.g., someone SSH-ing into this router).
FORWARD handles packets passing through this machine to reach another host on a different network. Routers mostly use FORWARD; end hosts mostly use INPUT/OUTPUT.


ITS352/DES352 · SIIT · Thammasat University