IPTABLES (Quick Learn)

10:49 PM / Diposting oleh Sharing IT / komentar (0)

Introduction 

Network security is a primary consideration in any decision to host a website as the threats are becoming more widespread and persistent every day. One means of providing additional protection is to invest in a firewall. Though prices are always falling, in some cases you may be able to create a comparable unit using the Linux iptables package on an existing server for little or no additional expenditure.

This chapter shows how to convert a Linux server into:

  • A firewall while simultaneously being your home website's mail, web and DNS server.
  • A router that will use NAT and port forwarding to both protect your home network and have another web server on your home network while sharing the public IP address of your firewall.
Creating an iptables firewall script requires many steps, but with the aid of the sample tutorials, you should be able to complete a configuration relatively quickly.

Packet Processing In iptables

All packets inspected by iptables pass through a sequence of built-in tables (queues) for processing. Each of these queues is dedicated to a particular type of packet activity and is controlled by an associated packet transformation/filtering chain.

There are three tables in total. The first is the mangle table which is responsible for the alteration of quality of service bits in the TCP header. This is hardly used in a home or SOHO environment.
The second table is the filter queue which is responsible for packet filtering. It has three built-in chains in which you can place your firewall policy rules. These are the:
  • Forward chain: Filters packets to servers protected by the firewall.
  • Input chain: Filters packets destined for the firewall.
  • Output chain: Filters packets originating from the firewall.
The third table is the nat queue which is responsible for network address translation. It has two built-in chains; these are:
  • Pre-routing chain: NATs packets when the destination address of the packet needs to be changed.
  • Post-routing chain: NATs packets when the source address of the packet needs to be changed

Processing For Packets Routed By The Firewall


Queue Type
Queue Function
Packet Transformation Chain in Queue
Chain Function
Filter
Packet filtering
FORWARD
Filters packets to servers accessible by another NIC on the firewall.
INPUT
Filters packets destined to the firewall.
OUTPUT
Filters packets originating from the firewall
Nat
Network Address Translation
PREROUTING
Address translation occurs before routing. Facilitates the transformation of the destination IP address to be compatible with the firewall's routing table. Used with NAT of the destination IP address, also known as destination NAT or DNAT.
POSTROUTING
Address translation occurs after routing. This implies that there was no need to modify the destination IP address of the packet as in pre-routing. Used with NAT of the source IP address using either one-to-one or many-to-one NAT. This is known as source NAT, or SNAT.
OUTPUT
Network address translation for packets generated by the firewall. (Rarely used in SOHO environments)
Mangle
TCP header modification
PREROUTING
POSTROUTING
OUTPUT
INPUT
FORWARD
Modification of the TCP packet quality of service bits before routing occurs. (Rarely used in SOHO environments)
  


You need to specify the table and the chain for each firewall rule you create. There is an exception: Most rules are related to filtering, so iptables assumes that any chain that's defined without an associated table will be a part of the filter table. The filter table is therefore the default.
To help make this clearer, take a look at the way packets are handled by iptables. In Figure 14.1 a TCP packet from the Internet arrives at the firewall's interface on Network A to create a data connection.
The packet is first examined by your rules in the mangle table's PREROUTING chain, if any. It is then inspected by the rules in the nat table's PREROUTING chain to see whether the packet requires DNAT. It is then routed.
If the packet is destined for a protected network, then it is filtered by the rules in the FORWARD chain of the filter table and, if necessary, the packet undergoes SNAT in the POSTROUTING chain before arriving at Network B. When the destination server decides to reply, the packet undergoes the same sequence of steps. Both the FORWARD and POSTROUTING chains may be configured to implement quality of service (QoS) features in their mangle tables, but this is not usually done in SOHO environments.
If the packet is destined for the firewall itself, then it passes through the mangle table of the INPUT chain, if configured, before being filtered by the rules in the INPUT chain of the filter table before. If it successfully passes these tests then it is processed by the intended application on the firewall.
At some point, the firewall needs to reply. This reply is routed and inspected by the rules in the OUTPUT chain of the mangle table, if any. Next, the rules in the OUTPUT chain of the nat table determine whether DNAT is required and the rules in the OUTPUT chain of the filter table are then inspected to help restrict unauthorized packets. Finally, before the packet is sent back to the Internet, SNAT and QoS mangling is done by the POSTROUTING chain

 Targets And Jumps

 Each firewall rule inspects each IP packet and then tries to identify it as the target of some sort of operation. Once a target is identified, the packet needs to jump over to it for further processing. Table 14.2 lists the built-in targets that iptables uses.

Descriptions Of The Most Commonly Used Targets

target Desciption Most Common Options
ACCEPT
  • iptables stops further processing.
  • The packet is handed over to the end application or the operating system for processing
N/A
DROP
  • iptables stops further processing.
  • The packet is blocked
N/A
LOG
  • The packet information is sent to the syslog daemon for logging
  • iptables continues processing with the next rule in the table
  • As you can't log and drop at the same time, it is common to have two similar rules in sequence. The first will log the packet, the second will drop it.
--log-prefix "string"
Tells iptables to prefix all log messages with a user defined string. Frequently used to tell why the logged packet was dropped
REJECT
  • Works like the DROP target, but will also return an error message to the host sending the packet that the packet was blocked
--reject-with qualifier
The qualifier tells what type of reject message is returned. Qualifiers include:
icmp-port-unreachable (default)
icmp-net-unreachable
icmp-host-unreachable
icmp-proto-unreachable
icmp-net-prohibited
icmp-host-prohibited
tcp-reset
echo-reply
DNAT
  • Used to do destination network address translation. ie. rewriting the destination IP address of the packet
--to-destination ipaddress
Tells iptables what the destination IP address should be
SNAT
  • Used to do source network address translation rewriting the source IP address of the packet
  • The source IP address is user defined
--to-source 
[-
][:-]
Specifies the source IP address and ports to be used by SNAT.
MASQUERADE
  • Used to do Source Network Address Translation.
  • By default the source IP address is the same as that used by the firewall's interface
[--to-ports [-]]
Specifies the range of source ports to which the original source port can be mapped.

Important Iptables Command Switch Operations

Each line of an iptables script not only has a jump, but they also have a number of command line options that are used to append rules to chains that match your defined packet characteristics, such the source IP address and TCP port. There are also options that can be used to just clear a chain so you can start all over again. Tables 14.2 through 14.6 list the most common options.

  General Iptables Match Criteria

iptables command Switch Desciption
-t <-table-> If you don't specify a table, then the filter table is assumed. As discussed before, the possible built-in tables include: filter, nat, mangle
-j Jump to the specified target chain when the packet matches the current rule.
-A Append rule to end of a chain
-F Flush. Deletes all the rules in the selected table
-p Match protocol. Types include, icmp, tcp, udp, and all
-s Match source IP address
-d Match destination IP address
-i Match "input" interface on which the packet enters.
-o Match "output" interface on which the packet exits

In this command switches example
iptables -A INPUT -s 0/0 -i eth0 -d 192.168.1.1  -p TCP -j ACCEPT
 
iptables is being configured to allow the firewall to accept TCP packets coming in on interface eth0 from any IP address destined for the firewall's IP address of 192.168.1.1. The 0/0 representation of an IP address means any.

  Common TCP and UDP Match Criteria

Switch Desciption
-p tcp --sport TCP source port. Can be a single value or a range in the format: start-port-number:end-port-number
-p tcp --dport TCP destination port. Can be a single value or a range in the format: starting-port:ending-port
-p tcp --syn Used to identify a new TCP connection request. ! --syn means, not a new connection request
-p udp --sport UDP source port. Can be a single value or a range in the format: starting-port:ending-port
-p udp --dport UDP destination port. Can be a single value or a range in the format: starting-port:ending-port

In this example:
iptables -A FORWARD -s 0/0 -i eth0 -d 192.168.1.58 -o eth1 -p TCP \
         --sport 1024:65535 --dport 80 -j ACCEPT
iptables is being configured to allow the firewall to accept TCP packets for routing when they enter on interface eth0 from any IP address and are destined for an IP address of 192.168.1.58 that is reachable via interface eth1. The source port is in the range 1024 to 65535 and the destination port is port 80 (www/http).

Common ICMP (Ping) Match Criteria

Matches used with ---icmp-type Desciption
--icmp-type The most commonly used types are echo-reply and echo-request

In this example:
iptables -A OUTPUT -p icmp --icmp-type echo-request -j ACCEPT
iptables -A INPUT  -p icmp --icmp-type echo-reply   -j ACCEPT
iptables is being configured to allow the firewall to send ICMP echo-requests (pings) and in turn, accept the expected ICMP echo-replies.
Consider another example
 
iptables -A INPUT -p icmp --icmp-type echo-request \
         -m limit --limit 1/s -i eth0 -j ACCEPT

The limit feature in iptables specifies the maximum average number of matches to allow per second. You can specify time intervals in the format /second, /minute, /hour, or /day, or you can use abbreviations so that 3/second is the same as 3/s.
In this example, ICMP echo requests are restricted to no more than one per second. When tuned correctly, this feature allows you to filter unusually high volumes of traffic that characterize denial of service (DOS) attacks and Internet worms.
 
iptables -A INPUT -p tcp --syn -m limit --limit 5/s -i eth0 -j ACCEPT

You can expand on the limit feature of iptables to reduce your vulnerability to certain types of denial of service attack. Here a defense for SYN flood attacks was created by limiting the acceptance of TCP segments with the SYN bit set to no more than five per second.
  
Common Extended Match Criteria
Switch Desciption
-m multiport --sports A variety of TCP/UDP source ports separated by commas. Unlike when -m isn't used, they do not have to be within a range.
-m multiport --dports A variety of TCP/UDP destination ports separated by commas. Unlike when -m isn't used, they do not have to be within a range.
-m multiport --ports A variety of TCP/UDP ports separated by commas. Source and destination ports are assumed to be the same and they do not have to be within a range.
-m --state The most frequently tested states are:
ESTABLISHED: The packet is part of a connection that has seen packets in both directions
NEW: The packet is the start of a new connection
RELATED: The packet is starting a new secondary connection. This is a common feature of such protocols such as an FTP data transfer, or an ICMP error.
INVALID: The packet couldn't be identified. Could be due to insufficient system resources, or ICMP errors that don't match an existing data flow.
This is an expansion on the previous example:
iptables -A FORWARD -s 0/0 -i eth0 -d 192.168.1.58 -o eth1 -p TCP \
         --sport 1024:65535 -m multiport --dports 80,443 -j ACCEPT
 
iptables -A FORWARD -d 0/0 -o eth0 -s 192.168.1.58 -i eth1 -p TCP \
         -m state --state ESTABLISHED -j ACCEPT
 
Here iptables is being configured to allow the firewall to accept TCP packets to be routed when they enter on interface eth0 from any IP address destined for IP address of 192.168.1.58 that is reachable via interface eth1. The source port is in the range 1024 to 65535 and the destination ports are port 80 (www/http) and 443 (https). The return packets from 192.168.1.58 are allowed to be accepted too. Instead of stating the source and destination ports, you can simply allow packets related to established connections using the -m state and --state ESTABLISHED options.

Using User Defined Chains

As you may remember, you can configure iptables to have user-defined chains. This feature is frequently used to help streamline the processing of packets. For example, instead of using a single, built-in chain for all protocols, you can use the chain to determine the protocol type for the packet and then hand off the actual final processing to a user-defined, protocol-specific chain in the filter table. In other words, you can replace a long chain with a stubby main chain pointing to multiple stubby chains, thereby shortening the total length of all chains the packet has to pass through. For example
iptables -A INPUT -i eth0  -d 206.229.110.2 -j fast-input-queue
iptables -A OUTPUT -o eth0 -s 206.229.110.2 -j fast-output-queue

iptables -A fast-input-queue  -p icmp -j icmp-queue-in
iptables -A fast-output-queue -p icmp -j icmp-queue-out

iptables -A icmp-queue-out -p icmp --icmp-type echo-request \
         -m state --state NEW -j ACCEPT

iptables -A icmp-queue-in -p icmp --icmp-type echo-reply -j ACCEPT
Here six queues help assist in improving processing speed. Table 14.7 summarizes the function of each.

Custom Queues Example Listing

Chain Desciption
INPUT The regular built-in INPUT chain in iptables
OUTPUT The regular built-in OUTPUT chain in iptables
fast-input-queue Input chain dedicated to identifying specific protocols and shunting the packets to protocol specific chains.
fast-output-queue Output chain dedicated to identifying specific protocols and shunting the packets to protocol specific chains.
icmp-queue-out Output queue dedicated to ICMP
icmp-queue-in Input queue dedicated to ICMP


Label: ,

Web Local (Web Server Linux) dapat di akses di Internet

12:58 PM / Diposting oleh Sharing IT / komentar (0)

Pada proyek ini, saya mempunyai sebuah server Proxy dengan memiliki IP static public dan sebuah Web Server Local, dimana rencana nya memanfaat kan ip public yang static ini, untuk dapat mengakses web server local.

misal :
1. IP public Static 110.80.77.224
2. IP Web Server Local : 163.158.50.83

#hapus semua Configurasi Firewall
iptables -F
iptables -X
iptables -t nat -F
iptables -t nat -X
iptables -t mangle -F
iptables -t mangle -X


# buka semua Port yang dibutuhkan oleh web local
iptables -A INPUT -i eth1 -p tcp -m multiport --dports 80,8080 -m state --state NEW,ESTABLISHED -j ACCEPT
iptables -A OUTPUT -o eth1 -p tcp -m multiport --sports 80,8080 -m state --state ESTABLISHED -j ACCEPT
iptables -A INPUT -i eth0 -p tcp -m multiport --dports 80,8080 -m state --state NEW,ESTABLISHED -j ACCEPT
iptables -A OUTPUT -o eth0 -p tcp -m multiport --sports 80,8080 -m state --state ESTABLISHED -j ACCEPT


# Direct ke ip web server local
 iptables -t nat -I PREROUTING -p tcp -s 0/0 --dport 80  -j DNAT --to-destination 163.158.50.83:80

Testing di browser :
http://110.80.77.224

## Documentation only

Label: ,

Fedora 7 stuck on 800X600 Screen Resolution

4:34 PM / Diposting oleh Sharing IT / komentar (6)

Type this command "xrandr -q"

This list will appear :

Screen 0: minimum 320 x 240, current 1024 x 768, maximum 1024 x 768
default connected 1024x768+0+0 0mm x 0mm
1024x768 60.0
1024x576 60.0
960x600 60.0
960x540 60.0
800x600 60.0 * 56.0
768x576 60.0
720x576 60.0
856x480 60.0
800x480 60.0
720x480 61.0
640x480 67.0 60.0
720x400 70.0
512x384 60.0
400x300 60.0
320x240 61.0

Now change it to whatever you had
Example for 1024 x 768

Type this command "xrandr -s 0"

Label:

Membuat Proxy Server Dengan CENTOS 5 / FEDORA 7.0

11:57 AM / Diposting oleh Sharing IT / komentar (1)

Siapkan 1 CPU server untuk internet, dengan menggunakan 2 LANCARD

Biasanya sebuah mainboard hanya di siapkan satu LANCARD onboard, bearti anda harus memnambahkan satu buah lancard lagi di dalamnya. Saat ini saya menggunakan 1 lancard dengan merk D-Link DFE – 528 TX.

Setelah di plug in dan OS nya sudah ready, pada terminal ketikkan :

[root@misdept /]# dmesg ax |grep eth

eth0: SiS 900 PCI Fast Ethernet at 0xa800, IRQ 217, 00:50:8d:c3:39:7d.

eth1: RealTek RTL8139 at 0xffffc20000022000, 00:1e:58:31:b3:eb, IRQ 209

eth1: Identified 8139 chip type 'RTL-8100B/8139D'

eth0: Media Link On 100mbps full-duplex

eth1: link up, 100Mbps, full-duplex, lpa 0x45E1

eth0: no IPv6 routers present

eth1: no IPv6 routers present

eth0: Media Link On 100mbps full-duplex

eth1: link up, 100Mbps, full-duplex, lpa 0x45E1

eth0: no IPv6 routers present

eth1: no IPv6 routers present

Tampak hasil yang di tampilkan ada 2 ethernet card yaitu eth0 dan eth1. Dimana yang eth0 adalah ethernet onboard pada mainboard saya, dan untuk eth1 adalah lancard tambahan yang saya berikan kedalam PC tsb. Dari hasil tampilan di atas, menunjukkan kalau OS diatas sudah berhasil mendeteksi adanya LANCARD baru, tapi belum aktif.

Bila di lakukan pengecekan IP : maka :

[root@misdept /]# ifconfig

eth0 Link encap:Ethernet HWaddr 00:50:8D:C3:39:7D

inet addr:192.168.0.105 Bcast:192.168.0.255 Mask:255.255.255.0

inet6 addr: fe80::250:8dff:fec3:397d/64 Scope:Link

UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1

RX packets:44415 errors:0 dropped:0 overruns:0 frame:0

TX packets:148493 errors:0 dropped:0 overruns:0 carrier:0

collisions:0 txqueuelen:1000

RX bytes:4944199 (4.7 MiB) TX bytes:143933894 (137.2 MiB)

Interrupt:217 Base address:0xa800

lo Link encap:Local Loopback

inet addr:127.0.0.1 Mask:255.0.0.0

inet6 addr: ::1/128 Scope:Host

UP LOOPBACK RUNNING MTU:16436 Metric:1

RX packets:1251 errors:0 dropped:0 overruns:0 frame:0

TX packets:1251 errors:0 dropped:0 overruns:0 carrier:0

collisions:0 txqueuelen:0

RX bytes:2074128 (1.9 MiB) TX bytes:2074128 (1.9 MiB)

Yang aktif tampak hanya eth0 saja, untuk mengaktifkan nya, pakai perintah :

[root@misdept/]# ifconfig eth01 up.

Setelah aktif, buatlah ip address pada NIC yang baru ini, sebagai contoh saya buat ip address 192.168.100.96. dan saya cek dengan ifconfig, hasilnya :

[root@misdept /]# ifconfig

eth0 Link encap:Ethernet HWaddr 00:50:8D:C3:39:7D

inet addr:192.168.0.105 Bcast:192.168.0.255 Mask:255.255.255.0

inet6 addr: fe80::250:8dff:fec3:397d/64 Scope:Link

UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1

RX packets:44415 errors:0 dropped:0 overruns:0 frame:0

TX packets:148493 errors:0 dropped:0 overruns:0 carrier:0

collisions:0 txqueuelen:1000

RX bytes:4944199 (4.7 MiB) TX bytes:143933894 (137.2 MiB)

Interrupt:217 Base address:0xa800

eth1 Link encap:Ethernet HWaddr 00:1E:58:31:B3:EB

inet addr:192.168.100.96 Bcast:192.168.100.255 Mask:255.255.255.0

inet6 addr: fe80::21e:58ff:fe31:b3eb/64 Scope:Link

UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1

RX packets:69669 errors:0 dropped:0 overruns:0 frame:0

TX packets:592 errors:0 dropped:0 overruns:0 carrier:0

collisions:0 txqueuelen:1000

RX bytes:6868331 (6.5 MiB) TX bytes:87821 (85.7 KiB)

Interrupt:209 Base address:0x2000

lo Link encap:Local Loopback

inet addr:127.0.0.1 Mask:255.0.0.0

inet6 addr: ::1/128 Scope:Host

UP LOOPBACK RUNNING MTU:16436 Metric:1

RX packets:1251 errors:0 dropped:0 overruns:0 frame:0

TX packets:1251 errors:0 dropped:0 overruns:0 carrier:0

collisions:0 txqueuelen:0

RX bytes:2074128 (1.9 MiB) TX bytes:2074128 (1.9 MiB)

Untuk LAN CARD sudah selesai, dan fungsi dari 2 LAN Card ini adalah, salah satu dari LAN Card ini di hubungkan ke LAN, dan satunya lagi di hubungkan ke Modem ADSL.

Saat nya aktifkan squid anda, dengan cara ketik Setup pada terminal, pilih System Service, dan centang Squid. Tekan OK dan Quit.

Lakukan setting ini pada root :

Konfigurasi dari root:
1.cd /etc/squid
2.backup configurasi squidnya : dengan perintah #cp squid.conf squid.conf.backup

3. Buat folder dan buat folder yangbaru menjadi owner dari user squid

[root@misdept /]# mkdir -p /home/cache/squid

[root@misdept /]# chown -R squid:squid /home/cache/squid

4.Buatlah folder spool

[root@misdept/]# mkdir /home/cache/squid/spool

[root@misdept/]# chown -R squid:squid /home/cache/squid

5. Selanjutnya adalah mengconfigurasi squid.conf dan bagian2 yang perlu di edit dari squid.conf adalah
a. edit http_portnya yaitu bagian

# http_port 3128

menjadi

http_port 3128

b. edit cache lognya

# cache_log /var/log/squid/cache.log

menjadi

cache_log /home/cache/squid/cache.log

c. edit cache_store_log

# cache_store_log /var/log/squid/store.log

menjadi

cache_store_log /home/cache/squid/store.log

d. Edit memori yang dialokasikan buat menjalankan squidnya, sesuaikan dengan kemampuan squid servernya. :)

# cache_mem 8 MB

menjadi

cache_mem 16 MB

e. Edit cache dir nya, arahkan sesuai dengan langkah no 5 dan juga space alokasinya yaitu

3072 M

# cache_dir ufs /var/spool/squid 100 16 256

menjadi

cache_dir ufs /home/cache/squid/spool 3072 16 256

f. Tinggal tambahin network yang mau di allowed untuk access proxy servernya
cari bagian :

#Recommended minimum configuration:

acl all src 0.0.0.0/0.0.0.0

acl manager proto cache_object

acl localhost src 127.0.0.1/255.255.255.255

acl to_localhost dst 127.0.0.0/8

acl SSL_ports port 443 563

acl Safe_ports port 80 # http

acl Safe_ports port 21 # ftp



acl Safe_ports port 443 563 # https, snews

acl Safe_ports port 70 # gopher

acl Safe_ports port 210 # wais

acl Safe_ports port 1025-65535 # unregistered ports

acl Safe_ports port 280 # http-mgmt

acl Safe_ports port 488 # gss-http

acl Safe_ports port 591 # filemaker

acl Safe_ports port 777 # multiling http

acl CONNECT method CONNECT

dibawah acl localhost src 127.0.0.1/255.255.255.255, tambahkan network yang akan di allowed

acl net1 src 172.17.3.0/255.255.255.0

acl net2 src 192.168.0.0/255.255.255.0

setelah itu supaya net1 dan net2 td bisa mengakses squid maka tambahkan http_access allow
cari baris :

#And finally deny all other access to this proxy

http_access allow localhost

http_access deny all

diantar http_access allow localhost dan http_access deny all tambahkan :

http_access allow net1

http_access allow net2

baris ini bisa taruh di atas http_access allow localhost atau dibawah http_access allow localhost yang penting diatas http_access deny all

6. Simpan dan start Squid nya

[root@misdept /]# /etc/init.d/squid start

7.Gunakan testing squidnya menggunakan browser sambil di lihat acess log nya

[root@misdept /]# tail -f /home/cache/squid/access.log

8. Ok thx itu dulu dari saya.

Label:

Membuat Server IRC dengan BEWARE IRC

11:53 AM / Diposting oleh Sharing IT / komentar (0)

Menurut saya, server IRC yang paling sederhana settingannya adalah Beware IRC, saya sudah membuatnya di Fedora 7.0. Coba di download saja di = http://ircd.bircd.org/
Anda akan mendapatkan file : bewareircd-linux.tar.gz
Lakukan Extrak dari file itu dengan cara : (ini contoh di Server saya)
[root@mis09 bafrin]# tar zxfv bewareircd-linux.tar.gz
Dan nantinya akan mendapatkan folder = bircd.
Berikut ini adalah isi dari folder bircd
[root@mis09 bircd]# ls -al
total 1056
drwx------ 2 1000 1000 4096 2008-06-25 14:16 .
drwx------ 29 bafrin bafrin 4096 2008-06-25 14:06 ..
-rwx------ 1 1000 1000 777588 2004-07-14 03:36 bircd
-rw------- 1 1000 1000 5907 2008-06-25 15:16 bircd.ini
-rw-r--r-- 1 root root 6 2008-06-25 15:17 bircd.pid
-rw------- 1 1000 1000 3745 2004-07-14 03:36 bircd-qnet.ini
-rw------- 1 1000 1000 108 2004-07-14 03:36 bircd.txt
-rw------- 1 1000 1000 15825 2004-07-14 03:36 example.conf
-rw------- 1 1000 1000 1874 2008-06-25 14:36 ircd.conf
-rw------- 1 1000 1000 0 2004-07-14 03:36 ircd.motd
-rwx------ 1 1000 1000 223684 2004-07-14 03:36 mkpasswd
-rwx------ 1 1000 1000 27 2004-07-14 03:36 rehash
-rwx------ 1 1000 1000 30 2004-07-14 03:36 restart
-rw-r--r-- 1 root root 73 2008-06-25 15:17 stdout.txt
-rwx------ 1 1000 1000 22 2004-07-14 03:36 stop
[root@mis09 bircd]#
step berikutnya tinggal 2 langkah saja, yaitu setting file bircd.ini dan ircd.conf

1. Setting bircd.ini sesuaikan dengan settingan saya :
a. Cari lah Hub, Ident, LookupNotice dan buatlah seperti ini, berilah tanda #, spy jangan di executed :
#Hub=1
#; This server can be hub
#Ident=1
#; identd lookup is performed to get a user's userid
#LookupNotice=1
#; the notices like "*** looking up your hostname"
b. Untuk panjang nick name dapat di atur di sini, saya buat panjang dari nick_name hanya 15 char saja:
MaxNick=15
; maximum length of a nick
c. Untuk memberi nama pada irc anda, buatlah spt ini (saya memberikan nama irc saya ebenezer-irc) :
NetworkName=ebenezer-irc
; if non-null, name is shown as NETWORK= token. must not contain spaces.

2. Langkah ke dua, setting. ircd.conf, buatlah seperti ini :

[root@mis09 bircd]# cat ircd.conf
# servername::server description::numeric.
# change numeric to something unique on the network

M:Stella.rosewood:*:irc-backup:0:1

# accept connections on port 6667 (clients) and port 4400 (servers)

P:::C:6667
#P:::S:4400

# standard Y-lines
# client class: ping freq 90, no autoconnect, no limit on connections, 80k sendQ
# oper class (same as client class)
# server class: ping freq 30, connect freq 300 secs, no limit on connections, 3M sendQ

Y:90:90:300:1:1700000
Y:80:90:300:1:1700000
Y:70:90:300:1:1700000

# standard I-line, accept everyone, max. 99 clones, if you have ip NAT

I:*@*:99:*@*::1

# standard I-line for IPv6 connections: max 5 clones from a /48
#I:"*@::/0":5/48:nomatch::1

# C-line for accepting services connection on same machine
# if you change these values, change them in bircserv.cfg as well.

C:192.168.0.108:pass:services.server.name::20

# which server has services power
# and which nicks are reserved (cannot be set by local clients)

#U:services.server.name:ChanServ,NickServ,MemoServ,OperServ:

# every server can be hub

#H:*::*:

# syntax for O:lines (needed to become IRCop)
# fill in your mask, your password, your name
# type /oper name password, in the irc client, to use.
#
# to encrypt your password, run mkpasswd, type your password,
# press enter, use the output string as shown in the example.

#O:mask:G26wOktjJIG0[OxXB5PrUlw3:name::10

# syntax for S:lines
# S:::<*.host.cc|a.b.c.*|CIDR>:
#
# example
# S:network.org:pass:1.2.3.4:*
#
# Oper Sethost: /sethost
# /mode +h @
# User Sethost: /sethost
# /mode +h
# (text taken from quakenet asuka)
# make sure sethost=1 and vhoststyle= non 0 in bircd.ini
[root@mis09 bircd]#

Setelah semua selesai, jalankan irc nya dengan cara :
[root@mis09 bircd]# ./bircd
Dan cek service job id nya apakah sudah running ?
[root@mis09 bircd]# ps ax |grep bircd
28942 pts/0 S 0:00 ./bircd
29010 pts/0 R+ 0:00 grep bircd
[root@mis09 bircd]#
IRC anda sudah running, bisa lsg di pakai nih......
oh.. ya.. saya lupa satu lagi.. Gimana kalo server anda harus down, krn listrik di ktr anda padam?? dan apakah kalo di On kan, otomatis service dari bircd bisa otomatis jalan sendiri??

Ok deh.. ini dia aku kasi tau .....
Perlu di ketahui.. saat ini, posisi folder bircd saya ada di :
[root@mis09 bircd]# pwd
/home/bafrin/bircd
terlebih dahulu buat lah file yang isinya script seperti ini, dan simpanlah dengan nama bircd :
[root@mis09 ftpuser]# cat bircd
#!/bin/bash
#
# Run-level Startup script for Bircd
#
# chkconfig: 345 91 19
export PATH=$PATH:/home/bafrin/bircd
# description: Startup/Shutdown Bircd
# if the executables do not exist -- display error
# depending on parameter -- startup, shutdown, restart
# of the instance and listener or usage display
case "$1" in
start)
# Bircd start
echo -n "Starting Bircd: "
/home/bafrin/bircd/bircd
echo "OK"
;;
stop)
# Bircd stop
echo -n "Shutdown Bircd: "
/home/bafrin/bircd/stop
echo "OK"
;;
*)
echo "Usage: $0 start|stop"
exit 1
esac
exit 0

Perhatikan, script ini untuk posisi folder bircd nya. (sesuaikan dengan folder bircd di server anda)
stelah selesai, simpan.
Copykan file bircd ke /etc/init.d/
dan perhatikan untuk mode dari file tsb :
-rw-r--r-- 1 ftpuser ftpuser 672 2008-06-27 14:34 bircd
buatlah supaya file tsb bisa di executed, dengan perintah :
[root@mis09 ftpuser]# chmod +x bircd
Tahap selanjutnya, adalah menambahkan service bircd supaya bisa di run pada level tertentu, saat ini saya mau buat dia aktif di runlevel 3 & 5
[root@mis09 ftpuser]# chkconfig --add bircd
dan setelah itu aktifkan pada run level 3 & 5 ;
[root@mis09 ftpuser]# chkconfig --levels 35 bircd on

Ok .. gitu aja... dan coba pastikan server anda, restart, dan cek dengan perintah :
[root@mis09 bafrin]# ps ax |grep bircd
2085 ? S 0:00 /home/bafrin/bircd/bircd
2786 pts/1 R+ 0:00 grep bircd

Tampak sudah running bircd nya... OK deh.. itu aja dari saya, Thx (hitung2 sebagai dokumentasi saya, supaya ngak lupa...)

Label:

Membuat Server IRC dengan Bahamut IRC

11:50 AM / Diposting oleh Sharing IT / komentar (2)

Internet Relay Chat (IRC) adalah suatu bentuk komunikasi di Internet yang diciptakan untuk komunikasi kelompok di tempat diskusi yang dinamakan channel (saluran), tetapi juga bisa untuk komunikasi jalur pribadi.

IRC diciptakan oleh Jarkko Oikarinen (nickname "WiZ") pada akhir Agustus 1988 untuk menggantikan program di BBS yang disebut MUT (MultiUser Talk), di Finlandia di sebut OuluBOX. Oikarinen menemukan inspirasi Bitnet Relay Chat yang beroperasi di dalam Jaringan Bitnet.

Saat ini saya sudah berhasil membuat server IRC dengan menggunakan BAHAMUT IRC pada FEDORA 7.0, untuk mendapatkannya silahkan download di : http://www.dal.net/?page=Bahamut

File yang di dapat adalah : bahamut-1.8.4-release.tar.gz

lakukanlah ekstrak di lokasi yang anda pilih, sebagai contoh saya membuat di lokasi yang saya pilih :
[root@mis09 bafrin]# tar zxfv bahamut-1.8.4-release.tar.gz
Setelah proses ekstrak selesai, maka akan terbentuk sebuah folder :

[root@mis09 bafrin]# ls
bahamut-1.8.4
bahamut-1.8.4-release.tar.gz Music
Desktop Pictures
Documents Public
Download Templates


Tampak folder bahamut-1.8.4
masuk ke dalam folder tsb, di dalam nya sudah ada :
[root@mis09 bafrin]# cd bahamut-1.8.4
[root@mis09 bahamut-1.8.4]# ls
CHANGES config.sub include LICENSE src
config.guess configure INSTALL Makefile TODO
config.log configure.in install-sh Makefile.in tools
config.status doc LICENCE.pcre README zlib
Untuk melihat cara instalasinya anda dapat membuka dan membaca file INSTALL
[root@mis09 bahamut-1.8.4]# nano INSTALL
dan isi dari File tsb :
HOW TO BUILD:
-------------
1. Run the configure script. It will setup include/setup.h and the
Makefiles to match your system:
./configure

Type ./configure --help to see different options. Most people will not
need to alter these.

2. [DISCOURAGED] Edit the the "include/config.h" file. This allows you to
change various options of how the ircd will operate. Usually the defaults
are OK.

3. "make" should build ircd.

4. "make install" will install the ircd, config converter, and documents
to the directory set by ./configure

5. Edit example.conf in your install directory, and move it to "ircd.conf".

6. Run the binary! ircd will look in the directory you are executing from
for an ircd.conf first, then it will look to the directory local to itself.
You may override these options by specifying a config file using:
./ircd -f path/to/ircd.conf

Best of luck!
-The Bahamut Team

$Id: INSTALL 1303 2006-12-07 03:23:17Z epiphani $
ikutin aja langkah2 nya,
dan nanti anada akan menemukan folder ircd di dalan root : [root@mis09 bahamut-1.8.4]# cd /root/ircd/
[root@mis09 ircd]# ls
convert_conf ircd ircd.motd ircd.pid mkpasswd opers.txt reference.conf template.conf
Copykan file template.conf menjadi ircd.conf
editlah ircd.conf, saat ini. ip server saya 192.168.90.108 (sesuaikan ip dari server anda)


# =========================================================================
# QUICKSTART: server configuration (see reference.conf for details)
# =========================================================================

/* server name and administration info */
global {
name not.configured; # IRC name of the server
info "located on earth"; # A short info line
admin {
"An unconfigured server"; # Three information lines sent
"An unknown administrator"; # in reply to ADMIN command
"email@somewhere.earth";
};
};

/* server options */
options {
network_name unconfigured; # A name is needed even if not linked
local_kline admin@server; # Contact email for server bans
show_links; # Show servers in LINKS
allow_split_ops; # Give ops in empty channels

// use these options when services is on the network
services_name services.name; # Name of services (NS/CS/MS/RS) server
stats_name stats.name; # Name of stats (OS/SS/HS) server
network_kline admin@net; # Contact email for network bans
nshelpurl "http://help"; # Nick registration help page

// if you need to link more than 1 server, uncomment the following line
# servtype hub;
};
/* where to listen for connections */
port {
port 6667; # Port to listen on
bind 192.168.90.108; # IP address to listen on
};

/* more listening ports */
#port { port 6668; bind 127.0.0.1; };
#port { port 6669; bind 127.0.0.1; };
#port { port 7000; bind 127.0.0.1; };

/* allow clients to connect */
allow {
host *@*; # Allow anyone
class users; # Place them in the users class
};

/* connection class for users */
class {
name users; # Class name
maxusers 1000; # Maximum connections
pingfreq 90; # Check idle connections every N seconds
maxsendq 100000; # 100KB send buffer limit
};

/* connection class for server operators */
class {
name opers;
pingfreq 90;
maxsendq 500000; # 500KB limit for opers
};

/* the server administrator */
oper {
name admin; # Username
passwd secret; # Password
access OAaRD; # Server Administrator
host *@192.168.0.*; # Must be connecting from here
host *@10.64.64.*; # Or from here
// insert other other hostmasks here
class opers; # Belongs in the opers class
};

/* for services */
super {
"services.name";
"stats.name";
// insert any other special servers here
};

/* reserved nicknames */
restrict { type nick; mask "NickServ"; reason "reserved for services"; };
restrict { type nick; mask "ChanServ"; reason "reserved for services"; };
restrict { type nick; mask "MemoServ"; reason "reserved for services"; };
restrict { type nick; mask "RootServ"; reason "reserved for services"; };
restrict { type nick; mask "OperServ"; reason "reserved for services"; };
restrict { type nick; mask "StatServ"; reason "reserved for services"; };
restrict { type nick; mask "HelpServ"; reason "reserved for services"; };
restrict { type nick; mask "services"; reason "reserved for services"; };


/* === these next two blocks are for linking to a hub === */

/* class for uplink hub */
class {
name hub;
pingfreq 120; # Idle check every 2 minutes
connfreq 300; # Try autoconnect every 5 minutes
maxsendq 1000000; # 1MB send queue
maxlinks 1; # Autoconnect to only 1 hub at a time
};

/* our uplink hub */
connect {
name hub.name; # Hub's IRC name
host 172.16.4.2; # Hub's IP address
port 7325; # Autoconnect to hub's port 7325
bind 127.0.0.1; # We connect from this IP
apasswd secret; # We accept this password from hub
cpasswd secret; # We send this password to hub
flags H; # It is a hub
class hub; # Use hub class
};


/* === these next two blocks are for linking to services === */

/* class for services */
class {
name services;
pingfreq 60; # Idle check every minute
maxsendq 5000000; # 5MB backlog buffer
};

/* our services */
connect {
name services.name; # Services' IRC name
host 192.168.90.108; # IP address services connects from
apasswd secret; # Password services sends
cpasswd secret; # Same password
class services;
};

Setelah selesai, ketiklah comannd :
[root@mis09 ircd]# ./ircd

bahamut-1.8(04) booting...
Security related issues should be sent to coders@dal.net
All other issues should be sent to dalnet-src@dal.net

Configuration Loaded.

Ircd is now becoming a daemon.
[root@mis09 ircd]#
Bila di cek service nya apakah sudah jalan ? dengan perintah :
[root@mis09 ircd]# ps ax |grep ircd
2875 ? Ss 0:00 ./ircd
2879 pts/0 R+ 0:00 grep ircd
[root@mis09 ircd]#
Server IRC anda sudah jalan, dan silahkan setting untuk irc clientnya.
Tampak service nya sudah jalan pada nomor service 2875, untuk mematikan service nya :

[root@mis09 ircd]# kill -KILL 2875

Label:

Reset root password for Centos 5.2

4:34 PM / Diposting oleh Sharing IT / komentar (0)

if you are server administrator, maybe you forget your root server password. There is a simple solution for you to reset your root password at Centos 5.2

1. Press enter if you see this section, your time just 3 seconds :


2. Press "e" for edit


3. Choose second list and press "e"


4. Fill 1 at the last line "... rhgb quiet" and press enter


5. Press "b" for continue booting

6. Type at sh-32# passwd root and press enter

7. Type your new password
Changing password for user root.
New UNIX password:

8. Type reboot and press Enter


Now your Centos 5.2 have a new password


Good luck

Label:

THE GREEN BERETS

5:18 PM / Diposting oleh Sharing IT / komentar (0)


http://www.youtube.com/watch?v=58QzTglCen8

Fighting soldiers from the sky,

Fearless men who jump and die.
Men who mean just what they say,
The brave men of the Green Beret.

Silver wings upon their chest,
These are men, America’s best.
One hundred men will test today,
But only three win the Green Beret.

Trained to live off nature’s land,
Trained in combat, hand-to-hand.
Men who fight by night and day,
Courage peaks from the Green Berets.

Silver wings upon their chest,
These are men, America’s best.
One hundred men will test today,
But only three win the Green Beret.

Fighting soldiers from the sky,
Fearless men who jump and die.
Men who mean just what they say,
The brave men of the Green Beret.



http://www.youtube.com/watch?v=LH4-tOqLH94&feature=related

Fighting soldiers from the sky,
Fearless men who jump and die.
Men who mean just what they say,
The brave men of the Green Beret.

Silver wings upon their chest,
These are men, America’s best.
One hundred men will test today,
But only three win the Green Beret.


Trained to live off nature’s land,
Trained in combat, hand-to-hand.
Men who fight by night and day,
Courage peaks from the Green Berets.

Silver wings upon their chest,
These are men, America’s best.
One hundred men will test today,
But only three win the Green Beret.

Back at home a young wife waits,
Her Green Beret has met his fate.
He has died for those oppressed,
Leaving her this last request:

"Put silver wings on my son’s chest,
Make him one of America’s best.
He’ll be a man, they’ll test one day,
Have him win the Green Beret."

Label:

Error JDBC Connection (Error Connecting: jdbcpostgresql:/ ....)

4:15 PM / Diposting oleh Sharing IT / komentar (2)

This a problem ;


It's a solution...

1. [root@pwmpku /]# cd /home/postgres/Adempiere/postgresql/8.2.0/pgdata/
Edit this statement =
host all all {your subnet/netmask} in pg_hba.conf
[root@pwmpku pgdata]# nano pg_hba.conf

TYPE DATABASE USER CIDR-ADDRESS METHOD

# "local" is for Unix domain socket connections only
local all all trust
# IPv4 local connections:
host all all 127.0.0.1/32 trust
# IPv6 local connections:
host all all ::1/128 trust
host all all 192.168.0.0/24 trust

2. cd /home/postgres/Adempiere/postgresql/8.2.0

3. [root@pwmpku 8.2.0]# . ./PGSQL.env

4. [root@pwmpku 8.2.0]# cd bin/

5. [root@pwmpku bin]# ./pg_ctl restart

6. [root@pwmpku ~]# su - postgres

7. cd /home/postgres/Adempiere/postgresql/8.2.0/bin

8. [postgres@pwmpku bin]$ ./pg_ctl restart

waiting for server to shut down.... done
server stopped
server starting
[postgres@pwmpku bin]$ LOG: database system was shut down at 2011-01-18 11:59:00 WIT
LOG: checkpoint record is at 0/3E96498
LOG: redo record is at 0/3E96498; undo record is at 0/0; shutdown TRUE
LOG: next transaction ID: 0/5552; next OID: 108939
LOG: next MultiXactId: 1; next MultiXactOffset: 0
LOG: database system is ready

[postgres@pwmpku bin]$

And then you can continue test process connection :



good luck ! :)

Label:

Shutting Down Alsa very long at Ubuntu 8.10,.. a "Solution"

3:34 PM / Diposting oleh Sharing IT / komentar (0)

Actually, I found a "solution" too. It works in my case:

In /etc/init.d/alsa-utils
search comment the line "mute_and_zero_levels "$TARGET_CARD" || EXITSTATUS=1"
and give mark #,
"#mute_and_zero_levels "$TARGET_CARD" || EXITSTATUS=1".

The mute_and_zero_levels call waits a very long time.

Have nice day.. :)

Label:

Configure DNS Server Fedora 7 & 8

11:09 AM / Diposting oleh Sharing IT / komentar (0)

[root@brainwash /]# rpm -qa|grep bind
bind-libs-9.4.0-6.fc7
rpcbind-0.1.4-6.fc7
bind-9.4.0-6.fc7
ypbind-1.19-9.fc7
bind-utils-9.4.0-6.fc7
bind-chroot-9.4.0-6.fc7

[root@brainwash /]# nano /var/named/chroot/etc/named.conf
options {
listen-on port 53 { 127.0.0.1; 192.167.10.1; };
listen-on-v6 port 53 { ::1; };
directory "/var/named";
dump-file "/var/named/data/cache_dump.db";
statistics-file "/var/named/data/named_stats.txt";
memstatistics-file "/var/named/data/named_mem_stats.txt";
allow-query { localhost; 192.167.10.0/24; };
recursion yes;
};

logging {
channel default_debug {
file "data/named.run";
severity dynamic;
};
};

zone "." IN {
type hint;
file "named.ca";
};

#include "/etc/named.rfc1912.zones";


#### Edit by bafrin ####

zone "tester.net" IN {
type master;
file "tester.net.db";
};

zone "10.167.192.in-addr.arpa" IN {
type master;
file "tester.net.rev";
};

Make shorcut link file to /etc/
[root@brainwash /]# ln -sf /var/named/chroot/etc/named.conf /etc/

[root@brainwash /]# nano /var/named/chroot/var/named/tester.net.db
$TTL 86400
@ IN SOA brainwash.tester.net. test.tester.net.(
2010080200;
86400;
3600;
360000;
86400;
)
IN NS brainwash.tester.net.

brainwash.tester.net. IN A 192.167.10.1

[root@brainwash /]# nano /var/named/chroot/var/named/teseter.net.rev
$TTL 86400
@ IN SOA brainwash.tester.net. pwm.tester.net.(
2010080200;
86400;
3600;
360000;
86400;
)
IN NS brainwash.tester.net.
1 IN PTR brainwash.tester.net.

Make shortcut link file to /var/named/
[root@brainwash /]# ln -sf /var/named/chroot/var/named/tester.net.db /var/named/
[root@brainwash /]# ln -sf /var/named/chroot/var/named/tester.net.rev /var/named/

Edit file resolv.conf
[root@brainwash /]# nano /etc/resolv.conf
search tester.net
nameserver 192.167.10.1
nameserver 208.67.220.220
nameserver 208.67.222.222

Edit and Input file hosts
[root@brainwash /]# nano /etc/hosts
127.0.0.1 brainwash.tester brainwash localhost.localdomain localhost
192.167.10.1 brainwash.tester.net brainwash

Edit and Input file host.conf
[root@brainwash /]# nano /etc/host.conf
#order hosts,bind
order bin,host
multi on

Make your DNS Server automaticaly run after restart your system
[root@brainwash /]# chkconfig named on

Cek Your Service
[root@brainwash /]# netstat -an|grep 53
tcp 0 0 192.167.10.1:53 0.0.0.0:* LISTEN
tcp 0 0 127.0.0.1:53 0.0.0.0:* LISTEN
tcp 0 0 127.0.0.1:953 0.0.0.0:* LISTEN
tcp 0 0 ::1:53 :::* LISTEN
tcp 0 0 ::1:953 :::* LISTEN
udp 0 0 192.167.10.1:53 0.0.0.0:*
udp 0 0 127.0.0.1:53 0.0.0.0:*
udp 0 0 0.0.0.0:5353 0.0.0.0:*
udp 0 0 ::1:53 :::*
udp 0 0 :::5353 :::*

Cek Your DNS Server
[root@brainwash /]# nslookup brainwash.tester.net
Server: 192.167.10.1
Address: 192.167.10.1#53

Name: brainwash.tester.net
Address: 192.168.10.1

If output messages from your server that's above, Your DNS server is complete.

Label:

Someday by Michael W. Smith

12:33 PM / Diposting oleh Sharing IT / komentar (0)

i like this song, you can download from :

http://www.ziddu.com/download/10809188/MichaelWSmith-05-Someday.mp3.html


SOMEDAY
Words & Music:Michael W. Smith and Wayne Kirkpatrick

Sexual harassment - nuclear reactors
Natural disasters from here to L.A.
Drug importers
New World Order
Wars over borders
Murder on the subway

The social classes - high rise of taxes
Diplomats are passive with a promise again

Talk of recession - people in depression
Dow Jones, bank loans, the Japanese yen

Chorus 1:
I wait for Kingdom come
When love will be here to stay
It will change us everyone
Someday, someday

Violence in the movies
Drive-by shootings
Rioting and looting
With the boys in the hood

Cults and religions
Deadly premonitions
Fiery oppositions
Evil battling good

AIDS awareness
Temporary marriage
Pro-life, pro-choice
Roe v Wade

Ethics and the media
Tabloid T.V.
The Kennedy Conspiracy
The Trial of O.J.

Chorus 2:
I wait for Kingdom come
When love will be here to stay
It will change us everyone
Someday, someday
There peace will make a stand
and the anger will fall away
We'll see the lion with the lamb
Someday, someday, someday

Chorus 2

Label:

Amy Grant - I Will Remember You

4:06 PM / Diposting oleh Sharing IT / komentar (2)

Good Song... i like it.
you can download from :

http://www.ziddu.com/download/10678078/17-AmyGrant-IWillRememberYou.wav.html

and this lyric :

I will remember You
Amy grant/gary chapman/keith thomas
Copyright © 1991 age to age music, inc./riverstone music, inc./edward grant, inc./yellow elephant music, inc.

(ascap), adm. by reunion music group, inc.


I will be walking one day
Down a street far away
And see a face in the crowd and smile
Knowing how you made me laugh
Hearing sweet echoes of you from the past
I will remember you.

Look in my eyes while you’re near
Tell me what’s happening here
See that I don’t want to say good-bye
Our love is frozen in time
I’ll be your champion and you’ll be mine
So please remember
I will remember you.

Later on
When this fire is an ember
Later on
When the night’s not so tender
Given time
Though it’s hard to remember darlin’
I will be holding on
I’ll still be holding to you
I will remember you.

So many years come and gone
And yet the memory is strong
One word we never could learn
Good-bye
True love is frozen in time
I’ll be your champion and you’ll be mine
I will remember you
So please remember
I will remember you
I will remember you
I will remember you
I will remember you.

Label:

IPTables tutorial

10:10 AM / Diposting oleh Sharing IT / komentar (0)

1. Persiapan

Sebelum mulai, diharapkan pembaca sudah memiliki pengetahuan dasar mengenai TCP/IP karena hal ini merupakan dasar dari penggunaan IPTables. Ada (sangat) banyak resource yang mendokumentasikan konsep dasar tentang TCP/IP, baik itu secara online maupun cetak. Silahkan googling untuk mendapatkannya.

Hal berikutnya yang harus anda persiapkan adalah sebuah komputer yang terinstall Linux. Akan lebih baik jika komputer anda memiliki 2 buah network interface card, sebab bisa menjalankan fungsi packet forwarding. Disarankan anda menggunakan linux dengan kernel 2.4 ke atas, karena (setahu saya) linux dengan kernel 2.4 ke atas sudah memiliki dukungan IPTables secara default, sehingga anda tidak perlu mengkompilasi ulang kernel anda. Bagi anda yang menggunakan kernel 2.2 atau sebelumnya, anda harus melakukan kompilasi kernel untuk memasukkan dukungan IPTables. Silahkan lihat tutorial Kompilasi kernel 2.4.x di Linux oleh mas Asfik.

2. Pendahuluan

IPTables memiliki tiga macam daftar aturan bawaan dalam tabel penyaringan, daftar tersebut dinamakan rantai firewall (firewall chain) atau sering disebut chain saja. Ketiga chain tersebut adalah INPUT, OUTPUT dan FORWARD.


Pada diagram tersebut, lingkaran menggambarkan ketiga rantai atau chain. Pada saat sebuah paket sampai pada sebuah lingkaran, maka disitulah terjadi proses penyaringan. Rantai akan memutuskan nasib paket tersebut. Apabila keputusannnya adalah DROP, maka paket tersebut akan di-drop. Tetapi jika rantai memutuskan untuk ACCEPT, maka paket akan dilewatkan melalui diagram tersebut.

Sebuah rantai adalah aturan-aturan yang telah ditentukan. Setiap aturan menyatakan “jika paket memiliki informasi awal (header) seperti ini, maka inilah yang harus dilakukan terhadap paket”. Jika aturan tersebut tidak sesuai dengan paket, maka aturan berikutnya akan memproses paket tersebut. Apabila sampai aturan terakhir yang ada, paket tersebut belum memenuhi salah satu aturan, maka kernel akan melihat kebijakan bawaan (default) untuk memutuskan apa yang harus dilakukan kepada paket tersebut. Ada dua kebijakan bawaan yaitu default DROP dan default ACCEPT.

Jalannya sebuah paket melalui diagram tersebut bisa dicontohkan sebagai berikut:

Perjalanan paket yang diforward ke host yang lain

1. Paket berada pada jaringan fisik, contoh internet.
2. Paket masuk ke interface jaringan, contoh eth0.
3. Paket masuk ke chain PREROUTING pada table Mangle. Chain ini berfungsi untuk me-mangle (menghaluskan) paket, seperti merubah TOS, TTL dan lain-lain.
4. Paket masuk ke chain PREROUTING pada tabel nat. Chain ini berfungsi utamanya untuk melakukan DNAT (Destination Network Address Translation).
5. Paket mengalami keputusan routing, apakah akan diproses oleh host lokal atau diteruskan ke host lain.
6. Paket masuk ke chain FORWARD pada tabel filter. Disinlah proses pemfilteran yang utama terjadi.
7. Paket masuk ke chain POSTROUTING pada tabel nat. Chain ini berfungsi utamanya untuk melakukan SNAT (Source Network Address Translation).
8. Paket keluar menuju interface jaringan, contoh eth1.
9. Paket kembali berada pada jaringan fisik, contoh LAN.

Perjalanan paket yang ditujukan bagi host lokal

1. Paket berada dalam jaringan fisik, contoh internet.
2. Paket masuk ke interface jaringan, contoh eth0.
3. Paket masuk ke chain PREROUTING pada tabel mangle.
4. Paket masuk ke chain PREROUTING pada tabel nat.
5. Paket mengalami keputusan routing.
6. Paket masuk ke chain INPUT pada tabel filter untuk mengalami proses penyaringan.
7. Paket akan diterima oleh aplikasi lokal.

Perjalanan paket yang berasal dari host lokal

1. Aplikasi lokal menghasilkan paket data yang akan dikirimkan melalui jaringan.
2. Paket memasuki chain OUTPUT pada tabel mangle.
3. Paket memasuki chain OUTPUT pada tabel nat.
4. Paket memasuki chain OUTPUT pada tabel filter.
5. Paket mengalami keputusan routing, seperti ke mana paket harus pergi dan melalui interface mana.
6. Paket masuk ke chain POSTROUTING pada tabel NAT.
7. Paket masuk ke interface jaringan, contoh eth0.
8. Paket berada pada jaringan fisik, contoh internet.

3. Sintaks IPTables

iptables [-t table] command [match] [target/jump]

1. Table

IPTables memiliki 3 buah tabel, yaitu NAT, MANGLE dan FILTER. Penggunannya disesuaikan dengan sifat dan karakteristik masing-masing. Fungsi dari masing-masing tabel tersebut sebagai berikut :

  1. NAT : Secara umum digunakan untuk melakukan Network Address Translation. NAT adalah penggantian field alamat asal atau alamat tujuan dari sebuah paket.
  2. MANGLE : Digunakan untuk melakukan penghalusan (mangle) paket, seperti TTL, TOS dan MARK.
  3. FILTER : Secara umum, inilah pemfilteran paket yang sesungguhnya.. Di sini bisa dintukan apakah paket akan di-DROP, LOG, ACCEPT atau REJECT

2. Command

Command pada baris perintah IPTables akan memberitahu apa yang harus dilakukan terhadap lanjutan sintaks perintah. Umumnya dilakukan penambahan atau penghapusan sesuatu dari tabel atau yang lain.

Command

Keterangan

-A
--append

Perintah ini menambahkan aturan pada akhir chain. Aturan akan ditambahkan di akhir baris pada chain yang bersangkutan, sehingga akan dieksekusi terakhir

-D         
--delete

Perintah ini menghapus suatu aturan pada chain. Dilakukan dengan cara menyebutkan secara lengkap perintah yang ingin dihapus atau dengan menyebutkan nomor baris dimana perintah akan dihapus.

-R         
--replace

Penggunaannya sama seperti --delete, tetapi command ini menggantinya dengan entry yang baru.

-I         
--insert

Memasukkan aturan pada suatu baris di chain. Aturan akan dimasukkan pada baris yang disebutkan, dan aturan awal yang menempati baris tersebut akan digeser ke bawah. Demikian pula baris-baris selanjutnya.

-L         
--list

Perintah ini menampilkan semua aturan pada sebuah tabel. Apabila tabel tidak disebutkan, maka seluruh aturan pada semua tabel akan ditampilkan, walaupun tidak ada aturan sama sekali pada sebuah tabel. Command ini bisa dikombinasikan dengan option –v (verbose), -n (numeric) dan –x (exact).

-F         
--flush

Perintah ini mengosongkan aturan pada sebuah chain. Apabila chain tidak disebutkan, maka semua chain akan di-flush.

-N         
--new-chain

Perintah tersebut akan membuat chain baru.

-X         
--delete-chain

Perintah ini akan menghapus chain yang disebutkan. Agar perintah di atas berhasil, tidak boleh ada aturan lain yang mengacu kepada chain tersebut.

-P         
--policy

Perintah ini membuat kebijakan default pada sebuah chain. Sehingga jika ada sebuah paket yang tidak memenuhi aturan pada baris-baris yang telah didefinisikan, maka paket akan diperlakukan sesuai dengan kebijakan default ini.

-E         
--rename-chain

Perintah ini akan merubah nama suatu chain.


3. Option

Option digunakan dikombinasikan dengan command tertentu yang akan menghasilkan suatu variasi perintah.

Option
Command          Pemakai

Keterangan

-v         
--verbose
--list         
--append
--insert
--delete
--replace

Memberikan output yang lebih detail, utamanya digunakan dengan --list. Jika digunakan dengan
--list, akan menampilkam K (x1.000),
M (1.000.000) dan G (1.000.000.000).

-x         
--exact
--list

Memberikan output yang lebih tepat.

-n         
--numeric
--list

Memberikan output yang berbentuk angka. Alamat IP dan nomor port akan ditampilkan dalam bentuk angka dan bukan hostname ataupun nama aplikasi/servis.

--line-number
--list

Akan menampilkan nomor dari daftar aturan. Hal ni akan mempermudah bagi kita untuk melakukan modifikasi aturan, jika kita mau meyisipkan atau menghapus aturan dengan nomor tertentu.

--modprobe
All

Memerintahkan IPTables untuk memanggil modul tertentu. Bisa digunakan bersamaan dengan semua command.

4. Generic Matches

Generic Matches artinya pendefinisian kriteria yang berlaku secara umum. Dengan kata lain, sintaks generic matches akan sama untuk semua protokol. Setelah protokol didefinisikan, maka baru didefinisikan aturan yang lebih spesifik yang dimiliki oleh protokol tersebut. Hal ini dilakukan karena tiap-tiap protokol memiliki karakteristik yang berbeda, sehingga memerlukan perlakuan khusus.

Match

Keterangan

-p         
--protocol

Digunakan untuk mengecek tipe protokol tertentu. Contoh protokol yang umum adalah TCP, UDP, ICMP dan ALL. Daftar protokol bisa dilihat pada /etc/protocols.

Tanda inversi juga bisa diberlakukan di sini, misal kita menghendaki semua protokol kecuali icmp, maka kita bisa menuliskan --protokol ! icmp yang berarti semua kecuali icmp.

-s         
--src
--source

Kriteria ini digunakan untuk mencocokkan paket berdasarkan alamat IP asal. Alamat di sini bisa berberntuk alamat tunggal seperti 192.168.1.1, atau suatu alamat network menggunakan netmask misal 192.168.1.0/255.255.255.0, atau bisa juga ditulis 192.168.1.0/24 yang artinya semua alamat 192.168.1.x. Kita juga bisa menggunakan inversi.

-d         
--dst
--destination

Digunakan untuk mecocokkan paket berdasarkan alamat tujuan. Penggunaannya sama dengan match –src

-i         
--in-interface

Match ini berguna untuk mencocokkan paket berdasarkan interface di mana paket datang. Match ini hanya berlaku pada chain INPUT, FORWARD dan PREROUTING

-o         
--out-interface

Berfungsi untuk mencocokkan paket berdasarkan interface di mana paket keluar. Penggunannya sama dengan
--in-interface. Berlaku untuk chain OUTPUT, FORWARD dan POSTROUTING

5. Implicit Matches

Implicit Matches adalah match yang spesifik untuk tipe protokol tertentu. Implicit Match merupakan sekumpulan rule yang akan diload setelah tipe protokol disebutkan. Ada 3 Implicit Match berlaku untuk tiga jenis protokol, yaitu TCP matches, UDP matches dan ICMP matches.

a. TCP matches

Match

Keterangan

--sport         
--source-port

Match ini berguna untuk mecocokkan paket berdasarkan port asal. Dalam hal ini kia bisa mendefinisikan nomor port atau nama service-nya. Daftar nama service dan nomor port yang bersesuaian dapat dilihat di /etc/services.

--sport juga bisa dituliskan untuk range port tertentu. Misalkan kita ingin mendefinisikan range antara port 22 sampai dengan 80, maka kita bisa menuliskan --sport 22:80.

Jika bagian salah satu bagian pada range tersebut kita hilangkan maka hal itu bisa kita artikan dari port 0, jika bagian kiri yang kita hilangkan, atau 65535 jika bagian kanan yang kita hilangkan. Contohnya --sport :80 artinya paket dengan port asal nol sampai dengan 80, atau --sport 1024: artinya paket dengan port asal 1024 sampai dengan 65535.Match ini juga mengenal inversi.

--dport          
--destination-port

Penggunaan match ini sama dengan match --source-port.

--tcp-flags

Digunakan untuk mencocokkan paket berdasarkan TCP flags yang ada pada paket tersebut. Pertama, pengecekan akan mengambil daftar flag yang akan diperbandingkan, dan kedua, akan memeriksa paket yang di-set 1, atau on.

Pada kedua list, masing-masing entry-nya harus dipisahkan oleh koma dan tidak boleh ada spasi antar entry, kecuali spasi antar kedua list. Match ini mengenali SYN,ACK,FIN,RST,URG, PSH. Selain itu kita juga menuliskan ALL dan NONE. Match ini juga bisa menggunakan inversi.

--syn

Match ini akan memeriksa apakah flag SYN di-set dan ACK dan FIN tidak di-set. Perintah ini sama artinya jika kita menggunakan match --tcp-flags SYN,ACK,FIN SYN

Paket dengan match di atas digunakan untuk melakukan request koneksi TCP yang baru terhadap server

b. UDP Matches

Karena bahwa protokol UDP bersifat connectionless, maka tidak ada flags yang mendeskripsikan status paket untuk untuk membuka atau menutup koneksi. Paket UDP juga tidak memerlukan acknowledgement. Sehingga Implicit Match untuk protokol UDP lebih sedikit daripada TCP.
Ada dua macam match untuk UDP:

--sport atau --source-port
--dport atau --destination-port

c. ICMP Matches

Paket ICMP digunakan untuk mengirimkan pesan-pesan kesalahan dan kondisi-kondisi jaringan yang lain. Hanya ada satu implicit match untuk tipe protokol ICMP, yaitu :

--icmp-type

6. Explicit Matches

a. MAC Address

Match jenis ini berguna untuk melakukan pencocokan paket berdasarkan MAC source address. Perlu diingat bahwa MAC hanya berfungsi untuk jaringan yang menggunakan teknologi ethernet.

iptables –A INPUT –m mac –mac-source 00:00:00:00:00:01

b. Multiport Matches

Ekstensi Multiport Matches digunakan untuk mendefinisikan port atau port range lebih dari satu, yang berfungsi jika ingin didefinisikan aturan yang sama untuk beberapa port. Tapi hal yang perlu diingat bahwa kita tidak bisa menggunakan port matching standard dan multiport matching dalam waktu yang bersamaan.

iptables –A INPUT –p tcp –m multiport --source-port 22,53,80,110

c. Owner Matches

Penggunaan match ini untuk mencocokkan paket berdasarkan pembuat atau pemilik/owner paket tersebut. Match ini bekerja dalam chain OUTPUT, akan tetapi penggunaan match ini tidak terlalu luas, sebab ada beberapa proses tidak memiliki owner (??).

iptables –A OUTPUT –m owner --uid-owner 500

Kita juga bisa memfilter berdasarkan group ID dengan sintaks --gid-owner. Salah satu penggunannya adalah bisa mencegah user selain yang dikehendaki untuk mengakses internet misalnya.

d. State Matches

Match ini mendefinisikan state apa saja yang cocok. Ada 4 state yang berlaku, yaitu NEW, ESTABLISHED, RELATED dan INVALID. NEW digunakan untuk paket yang akan memulai koneksi baru. ESTABLISHED digunakan jika koneksi telah tersambung dan paket-paketnya merupakan bagian dari koneki tersebut. RELATED digunakan untuk paket-paket yang bukan bagian dari koneksi tetapi masih berhubungan dengan koneksi tersebut, contohnya adalah FTP data transfer yang menyertai sebuah koneksi TCP atau UDP. INVALID adalah paket yang tidak bisa diidentifikasi, bukan merupakan bagian dari koneksi yang ada.

iptables –A INPUT –m state --state RELATED,ESTABLISHED

7. Target/Jump

Target atau jump adalah perlakuan yang diberikan terhadap paket-paket yang memenuhi kriteria atau match. Jump memerlukan sebuah chain yang lain dalam tabel yang sama. Chain tersebut nantinya akan dimasuki oleh paket yang memenuhi kriteria. Analoginya ialah chain baru nanti berlaku sebagai prosedur/fungsi dari program utama. Sebagai contoh dibuat sebuah chain yang bernama tcp_packets. Setelah ditambahkan aturan-aturan ke dalam chain tersebut, kemudian chain tersebut akan direferensi dari chain input.

iptables –A INPUT –p tcp –j tcp_packets
Target

Keterangan

-j ACCEPT
--jump ACCEPT

Ketika paket cocok dengan daftar match dan target ini diberlakukan, maka paket tidak akan melalui baris-baris aturan yang lain dalam chain tersebut atau chain yang lain yang mereferensi chain tersebut. Akan tetapi paket masih akan memasuki chain-chain pada tabel yang lain seperti biasa.

-j DROP
--jump DROP

Target ini men-drop paket dan menolak untuk memproses lebih jauh. Dalam beberapa kasus mungkin hal ini kurang baik, karena akan meninggalkan dead socket antara client dan server.

Paket yang menerima target DROP benar-benar mati dan target tidak akan mengirim informasi tambahan dalam bentuk apapun kepada client atau server.

-j RETURN
--jump RETURN

Target ini akan membuat paket berhenti melintasi aturan-aturan pada chain dimana paket tersebut menemui target RETURN. Jika chain merupakan subchain dari chain yang lain, maka paket akan kembali ke superset chain di atasnya dan masuk ke baris aturan berikutnya. Apabila chain adalah chain utama misalnya INPUT, maka paket akan dikembalikan kepada kebijakan default dari chain tersebut.

-j MIRROR

Apabila kompuuter A menjalankan target seperti contoh di atas, kemudian komputer B melakukan koneksi http ke komputer A, maka yang akan muncul pada browser adalah website komputer B itu sendiri. Karena fungsi utama target ini adalah membalik source address dan destination address.

Target ini bekerja pada chain INPUT, FORWARD dan PREROUTING atau chain buatan yang dipanggil melalui chain tersebut.

Beberapa target yang lain biasanya memerlukan parameter tambahan:

a. LOG Target

Ada beberapa option yang bisa digunakan bersamaan dengan target ini. Yang pertama adalah yang digunakan untuk menentukan tingkat log. Tingkatan log yang bisa digunakan adalah debug, info, notice, warning, err, crit, alert dan emerg.Yang kedua adalah -j LOG --log-prefix yang digunakan untuk memberikan string yang tertulis pada awalan log, sehingga memudahkan pembacaan log tersebut.

iptables –A FORWARD –p tcp –j LOG --log-level debug
iptables –A INPUT –p tcp –j LOG --log-prefix “INPUT Packets”

b. REJECT Target

Secara umum, REJECT bekerja seperti DROP, yaitu memblok paket dan menolak untuk memproses lebih lanjut paket tersebut. Tetapi, REJECT akan mengirimkan error message ke host pengirim paket tersebut. REJECT bekerja pada chain INPUT, OUTPUT dan FORWARD atau pada chain tambahan yang dipanggil dari ketiga chain tersebut.

iptables –A FORWARD –p tcp –dport 22 –j REJECT --reject-with icmp-host-unreachable

Ada beberapa tipe pesan yang bisa dikirimkan yaitu icmp-net-unreachable, icmp-host-unreachable, icmp-port-unreachable, icmp-proto-unrachable, icmp-net-prohibited dan icmp-host-prohibited.

c. SNAT Target

Target ini berguna untuk melakukan perubahan alamat asal dari paket (Source Network Address Translation). Target ini berlaku untuk tabel nat pada chain POSTROUTING, dan hanya di sinilah SNAT bisa dilakukan. Jika paket pertama dari sebuah koneksi mengalami SNAT, maka paket-paket berikutnya dalam koneksi tersebut juga akan mengalami hal yang sama.

iptables –t nat –A POSTROUTING –o eth0 –j SNAT --to-source 194.236.50.155-194.236.50.160:1024-32000

d. DNAT Target

Berkebalikan dengan SNAT, DNAT digunakan untuk melakukan translasi field alamat tujuan (Destination Network Address Translation) pada header dari paket-paket yang memenuhi kriteria match. DNAT hanya bekerja untuk tabel nat pada chain PREROUTING dan OUTPUT atau chain buatan yang dipanggil oleh kedua chain tersebut.

iptables –t nat –A PREROUTING –p tcp –d 15.45.23.67 --dport 80 –j DNAT --to-destination 192.168.0.2

e. MASQUERADE Target

Secara umum, target MASQUERADE bekerja dengan cara yang hampir sama seperti target SNAT, tetapi target ini tidak memerlukan option --to-source. MASQUERADE memang didesain untuk bekerja pada komputer dengan koneksi yang tidak tetap seperti dial-up atau DHCP yang akan memberi pada kita nomor IP yang berubah-ubah.

Seperti halnya pada SNAT, target ini hanya bekerja untuk tabel nat pada chain POSTROUTING.

iptables –t nat –A POSTROUTING –o ppp0 –j MASQUERADE

f. REDIRECT Target

Target REDIRECT digunakan untuk mengalihkan jurusan (redirect) paket ke mesin itu sendiri. Target ini umumnya digunakan untuk mengarahkan paket yang menuju suatu port tertentu untuk memasuki suatu aplikasi proxy, lebih jauh lagi hal ini sangat berguna untuk membangun sebuah sistem jaringan yang menggunakan transparent proxy. Contohnya kita ingin mengalihkan semua koneksi yang menuju port http untuk memasuki aplikasi http proxy misalnya squid. Target ini hanya bekerja untuk tabel nat pada chain PREROUTING dan OUTPUT atau pada chain buatan yang dipanggil dari kedua chain tersebut.

iptables –t nat –A PREROUTING –i eth1 –p tcp --dport 80 –j REDIRECT --to-port 3128

Referensi :
http://rootbox.or.id/tips/iptables.html

Label: