
Configuring iptables and ip6tables
Updating the Firewall 12-9
Updating the Firewall
All the preceding operations are first changed locally; nothing
has yet been changed on the LX unit. When you click Commit,
the GUI updates the local firewall configuration to the LX unit
iptables, and also creates a firewall configuration copy in the
LX unit.
L You must save the configuration for the changes to
take effect after a reboot (enter
save config flash
).
Configuring Packet Filters Using the
iptables and ip6tables Commands
Packet Filters are used to allow certain IP packets to pass, or not
pass, through an LX unit. Packet Filters can be applied to IP
packets that originate from the LAN side of the LX, or from the
LX unit itself.
On the LX unit (as on all Linux-based systems), Packet Filters
are known as chains. The INPUT chain filters packets coming
from the LAN to the LX; the OUTPUT chain filters packets from
the LX destined for the LAN.
L The LX unit also supports the FORWARD chain, which
filters packets that are to be forwarded to another
network. The FORWARD chain is used primarily in
routing environments rather than in console
management environments. For this reason, the
FORWARD chain is not covered in this chapter.
Click... To...
Commit propagate your changes and close the firewall window
Reload also propagate your changes, but leave the firewall window open
Close cancel all operations after the last update to the LX unit
Komentáře k této Příručce