WEBVTT

00:08.900 --> 00:14.720
Elephants will come back in this lesson we're going to learn how to set up an IP tables firewall in

00:14.720 --> 00:20.700
Linux in our business and we have learned how to use the you know blue firewall OK.

00:20.970 --> 00:26.430
But this I put it was always more out of once as compared to you of w firewall.

00:26.450 --> 00:27.010
OK.

00:27.140 --> 00:31.380
So let's see here practically how to use this file.

00:31.650 --> 00:31.970
OK.

00:31.970 --> 00:36.070
Before performing any operation Please log in as rude.

00:36.320 --> 00:41.010
And I want to explain some practical part of the IP firewall OK.

00:41.230 --> 00:45.100
I put the firewall locks on the basis of chains.

00:45.230 --> 00:48.030
There are three chains in this firewall.

00:48.170 --> 00:57.040
The first ones in question distend is used to set up the rules for incoming connections of some user

00:57.050 --> 01:03.170
trying to connect with a server then you can set up the rules for that kind of intimate connections.

01:03.260 --> 01:03.670
OK.

01:03.980 --> 01:07.800
The next one is of any sort of reply.

01:07.810 --> 01:12.730
I mean suppose you have a web server and if a client wants to connect to your server.

01:13.010 --> 01:16.480
Then in response you will sir replied some data.

01:16.550 --> 01:21.820
Ok so you can set up the rules OK on the basis of that reply.

01:21.930 --> 01:25.930
So you can block that reply with the help of this output chain.

01:26.080 --> 01:26.780
OK.

01:27.160 --> 01:29.030
And the next one is for.

01:29.420 --> 01:37.970
The forward is to really use to set up the rules for any local network which is how the forwarding options

01:37.990 --> 01:38.440
enable.

01:38.450 --> 01:41.360
Again the local network which have the forwarding.

01:41.470 --> 01:42.090
OK.

01:42.110 --> 01:47.320
So for example Nat network so you can set up the rules.

01:47.340 --> 01:47.620
OK.

01:47.630 --> 01:55.150
According to that network with the help of this forward 10 or so these treatments are there in.

01:55.280 --> 01:56.260
I party was.

01:56.270 --> 02:05.380
So you can perform either accept or reject or grow operations with the help of these treatments.

02:05.510 --> 02:09.670
You can either accept an IP reject or drop OK.

02:09.950 --> 02:14.520
So let's see here practically how to use this firewall.

02:15.110 --> 02:19.410
So first of all describe pin this of.

02:19.730 --> 02:23.410
And this is what I can address.

02:23.560 --> 02:34.790
Kate we can print this but to use this firewall just type IP tables then a hyphen a for and a new rule

02:34.850 --> 02:36.510
or a penny rule.

02:36.970 --> 02:39.440
And after that you need to provide the name.

02:39.470 --> 02:53.000
So I'm going to provide input and then I ask for a source so I get asked 10.0 dot dot 16.

02:53.350 --> 02:53.830
OK.

02:53.960 --> 02:57.010
And here I found the frontier for action.

02:57.100 --> 02:57.540
OK.

02:57.680 --> 02:58.850
And you need to proceed.

02:58.880 --> 03:01.710
I either accept drop or reject.

03:01.850 --> 03:02.520
OK.

03:02.600 --> 03:07.370
So just do X slowly drop.

03:07.460 --> 03:09.620
OK I want to grab these packets.

03:10.040 --> 03:10.470
OK.

03:10.490 --> 03:16.730
And now right think it ok you can see here it doesn't.

03:16.890 --> 03:18.510
Any reply ok.

03:18.660 --> 03:20.480
For the line.

03:20.580 --> 03:21.060
OK.

03:21.120 --> 03:23.830
Because you are trying to Pingo our own machines.

03:23.910 --> 03:31.760
That's why we are watching here in this 10.0 16 but we do not see any output.

03:31.990 --> 03:33.440
The ping.

03:34.490 --> 03:39.620
So this bill you can block an IP address for example input chain.

03:39.810 --> 03:40.450
OK.

03:40.920 --> 03:50.220
So if you want to view that who's just provide IP tables OK this will list the rules and if you want

03:50.220 --> 04:01.160
to see more that is just wrong and hype on the key it use more detailed information about our IP tables.

04:01.320 --> 04:02.390
Rules.

04:02.970 --> 04:05.230
In despair you can add a rule.

04:05.540 --> 04:06.080
OK.

04:06.300 --> 04:13.260
And of adding the rule I wish we could delete the rule so to delete the rule and just type IPTA was

04:15.020 --> 04:16.200
handy.

04:16.360 --> 04:23.860
And here you need to provide the name to destroy input because we have said the rule for input 10 and

04:24.080 --> 04:24.860
number.

04:24.940 --> 04:26.380
So we have only one rule.

04:26.380 --> 04:34.790
So that means that's why we won and he didn't again I put labels on here you can see there is Noorul

04:34.810 --> 04:36.890
present in this list.

04:37.250 --> 04:40.030
In this way you can add the rule Biliteral.

04:40.100 --> 04:40.770
OK.

04:40.980 --> 04:44.670
OK let's perform the same operation with terrible sort of thing.

04:44.950 --> 04:45.430
OK.

04:45.850 --> 04:54.300
So let's open up your Chrome browser and we now learn what web server works OK.

04:54.560 --> 04:59.170
You can see this is the output of all the whips were from this tool machine.

04:59.650 --> 05:14.670
So I want to set up the rule that these IP tables got put Jane and the souces and dot dot dot 16.

05:14.990 --> 05:17.010
Yes they drop.

05:17.390 --> 05:25.450
Well Kevin said this rule what happens is you can still access this website cause the House that the

05:26.110 --> 05:27.360
foreign put in.

05:27.490 --> 05:27.910
OK.

05:27.940 --> 05:33.510
And we can put in the help set the rules here that hyphenates.

05:33.800 --> 05:37.160
I finesse that means in the source source.

05:37.360 --> 05:45.820
And then you said the same rule with destination OK means distension means the replies that gonna get

05:45.820 --> 05:47.380
out from our server.

05:47.380 --> 05:47.890
OK.

05:47.980 --> 05:56.860
So what happens is this output gets blocked due to this rule by replacing this hyphen as it has been.

05:56.950 --> 06:00.000
OK let's refresh this page OK.

06:00.040 --> 06:05.750
You can see it is just moving around and around but is not showing anymore.

06:05.860 --> 06:08.100
Let's copy and paste here.

06:08.820 --> 06:09.210
OK.

06:09.220 --> 06:14.700
You can see there is no good because we have blocked the vidis hyphen.

06:14.740 --> 06:16.690
So what is this DNS.

06:16.690 --> 06:23.830
So if one is for a source IP address or give source IP address and head for the means destination IP

06:23.830 --> 06:24.500
address.

06:24.700 --> 06:25.090
So.

06:25.120 --> 06:34.250
So it means any IP for incoming and destination means IP for outgoing outgoing packets incoming packets.

06:34.400 --> 06:39.310
In this way you can set up the rules on the basis of source and destination as well.

06:39.440 --> 06:39.990
OK.

06:40.230 --> 06:40.970
OK.

06:40.990 --> 06:42.180
After this.

06:42.250 --> 06:48.420
Does that all the rules if you want to flush all the rules just type hyphen.

06:48.610 --> 06:50.880
OK this is called the rules.

06:50.910 --> 06:51.810
No.

06:53.690 --> 06:54.490
It's.

06:57.730 --> 06:58.090
OK.

06:58.110 --> 07:00.560
I will repeat is back.

07:00.790 --> 07:01.240
OK.

07:02.600 --> 07:07.970
So I want to show you how to set up the rules on the basis of.

07:08.720 --> 07:12.170
You can block a particular port on your system.

07:12.170 --> 07:12.630
OK.

07:12.770 --> 07:17.180
So first of all please install software here.

07:17.270 --> 07:18.830
This is a command line.

07:19.000 --> 07:22.200
Or you can call it d'Azyr this based browser.

07:22.370 --> 07:27.040
It is a browser Mitsos you know output in the form of text only.

07:27.290 --> 07:30.700
So just type Suro get install lynx.

07:30.760 --> 07:31.350
OK.

07:31.550 --> 07:37.610
So let's open our web server here on our local machine that is this virtual machine.

07:37.730 --> 07:38.230
OK.

07:38.420 --> 07:39.770
This is the same output.

07:39.770 --> 07:43.270
Here you can see Apache went to default page.

07:43.310 --> 07:46.280
You can see the same name here.

07:46.290 --> 07:48.520
I bet you want to default page.

07:49.100 --> 07:53.210
We are watching this or putting the text from this links browser.

07:53.630 --> 07:54.210
OK.

07:54.740 --> 07:57.680
So I want to blog this.

07:57.670 --> 07:58.980
Our server.

07:59.180 --> 07:59.550
OK.

07:59.630 --> 08:03.680
So you can block it on the basis of part of it.

08:03.830 --> 08:14.630
So we just typed IP tables again hyphen for a pen name in put here to be frugal that is DCP.

08:14.780 --> 08:15.640
OK.

08:16.230 --> 08:23.400
Here a sport that is so sport and so were by default users don't know what it is.

08:23.740 --> 08:24.230
OK.

08:24.410 --> 08:27.940
And you can send that to any other book by default.

08:27.960 --> 08:39.600
Every observer uses an ability and acknowledges the rule grop or you can also aggregate and long healing's

08:39.730 --> 08:40.990
tangled up.

08:41.030 --> 08:49.480
You got 16 and here you can see of that adding that rule you can get any are at the bottom here destroying

08:49.490 --> 08:51.030
that making connection.

08:51.170 --> 08:57.790
But it is not going to open any page here because Vihar block with the help of Google.

08:58.000 --> 08:58.510
OK.

08:58.730 --> 09:02.240
So just flush all the rules again

09:06.430 --> 09:16.790
here and then not OK because we have flushed all the rules and we can't play but you can block OK or

09:16.790 --> 09:21.280
you can add the rules on the basis of no particular application.

09:21.330 --> 09:24.260
It means on the basis of particular protocol.

09:24.350 --> 09:25.440
OK.

09:25.640 --> 09:32.880
So the application Despain Come on use this ICMP protocol OK to send the ping or get the reply.

09:32.920 --> 09:33.420
OK.

09:33.560 --> 09:39.870
So you can block only happens not the server or not the entire work.

09:39.950 --> 09:45.170
You can block only specific protocol that is the ICMP protocol.

09:45.320 --> 09:45.560
OK.

09:45.560 --> 09:47.200
With the help of this firewall.

09:47.480 --> 09:53.090
So in order to do that you need to rule like this was

09:55.650 --> 09:57.000
horrible.

09:57.060 --> 10:00.650
Then you put your iPhone before protocol.

10:00.720 --> 10:08.430
I see a B as in not zero Dot got 16.

10:08.500 --> 10:13.570
I fully grasp Franchi no type of thing.

10:13.670 --> 10:15.400
Then you've got 16

10:19.000 --> 10:25.920
OK we can't get any reply but just do links.

10:26.200 --> 10:30.510
You got to got 16 and get the browser open.

10:30.520 --> 10:30.960
OK.

10:31.210 --> 10:37.400
That means we are allowed to access this as practical but not with the same people only.

10:37.610 --> 10:38.110
OK.

10:38.200 --> 10:42.760
So you can set up the rules on the basis of these protocols.

10:43.090 --> 10:43.760
OK.

10:44.090 --> 10:51.090
OK after performing all these operations I will show you how to set up the rules for outputting or we

10:51.090 --> 10:52.550
can prove what would change.

10:52.780 --> 10:57.570
So I want to block our lips are out here on this browser.

10:57.820 --> 10:58.460
OK.

10:58.600 --> 11:13.440
So for that I be tables and E-4 up in a hearing to prod the chain that is outputting the source code

11:13.830 --> 11:24.370
to go 16 and here the action that is OK at this time use or reject action.

11:24.790 --> 11:34.840
And now go to browser based on IP address here and here you can see after adding the rule we can see

11:34.840 --> 11:36.910
in the output here it is this.

11:36.940 --> 11:38.720
Moving it around and around.

11:39.090 --> 11:39.540
OK.

11:39.660 --> 11:44.640
In this way you can block this sort one out with the help of output.

11:44.760 --> 11:46.370
OK.

11:46.600 --> 11:51.600
Now we learn how to set up the rules of input and output chain.

11:51.610 --> 11:55.490
And also with the help of specific broken protocol.

11:55.640 --> 11:56.140
OK.

11:56.300 --> 11:58.240
But adding the rules is not enough.

11:58.360 --> 11:58.650
OK.

11:58.660 --> 12:05.020
Because when you restart this machine all the rules get deleted from you are so good.

12:05.050 --> 12:12.780
So what do you do if you want to hold the girl back when if you've seen the starts.

12:12.790 --> 12:13.530
OK.

12:13.540 --> 12:16.670
So for that you need to do the following things.

12:16.690 --> 12:27.580
So first of all let's do was saying ok and show the part you see here.

12:27.580 --> 12:29.790
I believe it is not rules.

12:29.940 --> 12:31.040
OK.

12:31.450 --> 12:35.270
Enter again after doing this just Google

12:41.630 --> 12:43.490
opened this fine interface's

12:47.010 --> 12:55.010
here had this technique and these lines up IPTA most

12:57.810 --> 13:09.400
store who prefer IPTA was the store and here provide the part that leads the tables.

13:09.620 --> 13:11.510
You don't the rules give

13:14.580 --> 13:14.970
right to

13:19.870 --> 13:21.700
when you restart your machine.

13:21.730 --> 13:24.530
You will find only one is back.

13:24.550 --> 13:24.890
OK.

13:24.940 --> 13:26.720
As they are there before.

13:26.860 --> 13:27.380
OK.

13:27.580 --> 13:32.870
So in this way you can use these IP tables firewall to secure.

13:32.880 --> 13:34.310
So we're in detail.
