🔥 Lab 10 — Basic Linux Firewall · Cheat Sheet
ITS352/DES352 · SIIT · Thammasat University
1 · Firewall Concepts
A firewall sits between the internal network and the Internet — it forwards some packets and filters (drops) others based on rules in a filter table.
Three Chains
| Chain | Handles packets that are… | Analogy |
|---|---|---|
| INPUT | Destined for THIS machine | Mail addressed to the post office itself |
| FORWARD | Passing THROUGH this machine to another host | Mail passing through the post office |
| OUTPUT | Originating FROM this machine | Mail sent out by the post office |
[Incoming packet]
↓
Is it FOR this machine?
├── YES → INPUT chain → Local Process → OUTPUT chain → [out]
└── NO → FORWARD chain → [out to next hop]
Filter Table Criteria
Rules can match on: source/destination IP, source/destination port, protocol (tcp/udp/icmp), network interface
Rule Checking Order ⚠️
- Rules checked top to bottom, one by one
- First matching rule wins — remaining rules are skipped
- If no rule matches → DEFAULT RULE (policy) is applied ← quiz answer
2 · Firewall Strategies
| Strategy | Default Policy | Add rules to… | Security |
|---|---|---|---|
| Blacklisting | ACCEPT | DROP bad packets | Lower |
| Whitelisting | DROP | ACCEPT good packets | Higher ✅ |
Blacklisting = "let everyone in except the banned list"
Whitelisting = "only let approved people in — everyone else out" ← more secure, more popular
Quiz trap: To protect an internal network → INPUT = Whitelisting (DROP default), OUTPUT = Blacklisting(ACCEPT default)
3 · iptables Command Reference
Basic Commands
sudo iptables -nvL # View filter table (numeric, verbose, list all)
sudo iptables -F # Flush (delete) ALL rules in ALL chains
sudo iptables -F INPUT # Flush only INPUT chain rules
sudo iptables -F OUTPUT # Flush only OUTPUT chain rules
sudo iptables -F FORWARD # Flush only FORWARD chain rules
sudo iptables-save > rules.txt # Save rules to file
sudo iptables-restore < rules.txt # Restore rules from file-nvL output example:
Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 DROP icmp -- * * 192.168.198.0/24 0.0.0.0/0
0 0 DROP tcp -- * * 35.197.141.103 0.0.0.0/0
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy DROP 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
0 0 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
0 0 ACCEPT tcp -- * * 0.0.0.0/0 203.131.209.93
Set Default Policy
sudo iptables -P INPUT ACCEPT # Default: accept all incoming
sudo iptables -P INPUT DROP # Default: drop all incoming
sudo iptables -P OUTPUT ACCEPT # Default: accept all outgoing
sudo iptables -P OUTPUT DROP # Default: drop all outgoing
sudo iptables -P FORWARD ACCEPT # Default: accept all forwarded
sudo iptables -P FORWARD DROP # Default: drop all forwardedAdd / Insert / Delete Rules
Syntax:
sudo iptables <chain-action> <CHAIN> [rule options] -j <ACCEPT|DROP>| Flag | Action on chain |
|---|---|
-A CHAIN | Append rule at the END |
-I CHAIN N | Insert rule at position N |
-I CHAIN | Insert at the BEGINNING (position 1) |
-D CHAIN N | Delete rule number N |
-P CHAIN | Set default policy |
Rule Options
| Flag | Matches… | Example |
|---|---|---|
-s <ip/subnet> | Source IP or network | -s 192.168.1.0/24 |
-d <ip/subnet> | Destination IP or network | -d 203.131.209.93 |
-p <proto> | Protocol | -p tcp / -p udp / -p icmp |
--sport <port> | Source port | --sport 80 |
--dport <port> | Destination port | --dport 22 |
-i <NIC> | Incoming interface | -i eth0 |
-o <NIC> | Outgoing interface | -o eth1 |
| Action flag | Effect |
|---|---|
-j ACCEPT | Accept the packet |
-j DROP | Silently discard the packet |
4 · Command Examples with Expected Output
Allow incoming ping (ICMP) — quiz answer
sudo iptables -A INPUT -p icmp -j ACCEPTAllow incoming HTTP from a subnet
# Quiz answer format: allow HTTP from 192.168.200.0/24
sudo iptables -A INPUT -p tcp -s 192.168.200.0/24 --dport 80 -j ACCEPT
# Shorter accepted form (quiz showed):
sudo iptables -A INPUT -p tcp -s 192.168.200.0/24 -j ACCEPTBlock a website by domain name (OUTPUT)
# Block www.minecraftskins.com (TCP) — quiz answer
sudo iptables -A OUTPUT -p tcp -d www.minecraftskins.com -j DROP
# Block www.pantip.com
sudo iptables -A OUTPUT -p tcp -d www.pantip.com -j DROP
# → system auto-resolves domain to IPs, creates multiple DROP rulesReproduce the quiz's iptables -nvL output (3-point question)
Chain OUTPUT (policy DROP)
ACCEPT icmp 0.0.0.0/0 → 0.0.0.0/0
ACCEPT tcp 0.0.0.0/0 → 203.131.209.93
Commands to produce this:
# 1. Set default DROP for OUTPUT (whitelisting)
sudo iptables -P OUTPUT DROP
# 2. Accept all outgoing ICMP
sudo iptables -A OUTPUT -p icmp -j ACCEPT
# 3. Accept TCP to specific IP (203.131.209.93)
sudo iptables -A OUTPUT -p tcp -d 203.131.209.93 -j ACCEPT5 · Assignment Quick Reference
Assignment 1 — INPUT Blacklisting
sudo iptables -F INPUT
sudo iptables -P INPUT ACCEPT # default ACCEPT
sudo iptables -A INPUT -p icmp -s 192.168.198.0/24 -j DROP # rule 1: drop ICMP from subnet
sudo iptables -A INPUT -p tcp -s 35.197.141.103 -j DROP # rule 2: drop TCP from SIIT server
sudo iptables -nvLExpected tests: friend's ping → FAIL ✅ | www.siit.tu.ac.th → not load ✅ | www.tu.ac.th → loads ✅
Assignment 2 — INPUT Whitelisting
sudo iptables -F INPUT
sudo iptables -A INPUT -p icmp -s 192.168.198.0/24 -j ACCEPT # rule 1: accept ICMP from subnet
sudo iptables -P INPUT DROP # default DROP
sudo iptables -nvLExpected tests: friend's ping → SUCCEED ✅ | www.tu.ac.th → not load ✅ (HTTP blocked by default DROP)
Assignment 3 — OUTPUT Blacklisting
sudo iptables -F OUTPUT
sudo iptables -P OUTPUT ACCEPT # default ACCEPT
sudo iptables -A OUTPUT -p icmp -j DROP # rule 1: drop all outgoing ICMP
sudo iptables -A OUTPUT -p tcp -d www.pantip.com -j DROP # rule 2: drop TCP to pantip
sudo iptables -nvLExpected tests: ping friend → FAIL ✅ | pantip.com → not load ✅ | www.tu.ac.th → loads ✅
Assignment 4 — FORWARD Whitelisting (IMUNES)
# Router R1 (no sudo needed in IMUNES)
sysctl -w net.ipv4.ip_forward=1
iptables -F FORWARD
iptables -A FORWARD -p udp -s 192.168.5.0/24 -j ACCEPT # rule 1: accept UDP from Net A
iptables -A FORWARD -p icmp -j ACCEPT # rule 2: accept all ICMP
iptables -P FORWARD DROP # default DROP
iptables -nvL| Test | Result |
|---|---|
| A ping B | ✅ ICMP — matches rule 2 |
| B ping A | ✅ ICMP — matches rule 2 |
| A UDP → B | ✅ from Net A — matches rule 1 |
| B UDP → A | ❌ B is not in Net A — hits default DROP |
| A TCP → B | ❌ TCP not in rules — hits default DROP |
6 · Packet Flow — Which Chain is Used?
| Packet scenario | Chain used on the router/firewall |
|---|---|
| Packet arrives, addressed to this machine | INPUT |
| Packet arrives, going to another machine | FORWARD |
| Packet sent by this machine | OUTPUT |
| Router forwarding a packet between networks | FORWARD (NOT OUTPUT) |
⚠️ KEY: A packet passing through a router uses FORWARD, not OUTPUT.
OUTPUT only applies to packets the router itself generates.
7 · Quiz Question Patterns
| Question | Answer |
|---|---|
| Delete all existing firewall rules? | sudo iptables -F |
| Allow incoming ping (ICMP)? | sudo iptables -A INPUT -p icmp -j ACCEPT |
| Blocks all except known source = ? strategy | Whitelisting |
| No rule matches → firewall performs? | DEFAULT RULE (policy) |
| Command to set default for a chain? | sudo iptables -P <CHAIN> <ACCEPT|DROP> |
| Allow HTTP from 192.168.200.0/24? | sudo iptables -A INPUT -p tcp -s 192.168.200.0/24 -j ACCEPT |
| Block website www.minecraftskins.com (TCP)? | sudo iptables -A OUTPUT -p tcp -d www.minecraftskins.com -j DROP |
| Protect internal network: INPUT and OUTPUT strategy? | INPUT=Whitelisting, OUTPUT=Blacklisting |
| Which is more secure: black or white? | Whitelisting |
What does -A do? | Appends rule at the END of chain |
What does -I INPUT 1 do? | Inserts rule at BEGINNING (position 1) |
What does -F do? | Flushes (deletes) ALL rules |
What does -P do? | Sets the DEFAULT POLICY of a chain |
-s flag means? | Source IP/network |
-d flag means? | Destination IP/network |
-p icmp matches? | Ping packets (ICMP protocol) |
--dport 80 means? | Destination port 80 (HTTP) |
3-point Long Answer: Write commands to produce a given iptables -nvL output
Strategy: Read the output → identify default policy → identify each rule in order
OUTPUT (policy DROP) → sudo iptables -P OUTPUT DROP # set default first
ACCEPT icmp any→any → sudo iptables -A OUTPUT -p icmp -j ACCEPT
ACCEPT tcp any→IP → sudo iptables -A OUTPUT -p tcp -d <IP> -j ACCEPT
Explanation: Why whitelisting is more secure
Whitelisting sets the default to DROP, so any unknown or new attack traffic is automatically blocked. You only allow what you explicitly trust. Blacklisting defaults to ACCEPT, so new threats can get through until you add a specific block rule — you can never know all the bad ones in advance.
Explanation: Difference between INPUT and FORWARD
INPUT handles packets addressed to this machine itself (e.g., someone SSH-ing into this router).
FORWARD handles packets passing through this machine to reach another host on a different network. Routers mostly use FORWARD; end hosts mostly use INPUT/OUTPUT.
ITS352/DES352 · SIIT · Thammasat University