<?xml version="1.0" encoding="iso-8859-1"?>
<rss version="2.0">
<channel>
  <title>Linux Format forums</title>
  <link>http://www.linuxformat.com/forums/index.php</link>
  <description>Help, discussion, magazine feedback and more</description>
  <language>english</language>
  <copyright>(c) Copyright Thu May 23, 2013 8:18 am by Linux Format forums</copyright>
  <managingEditor>webmaster@linuxformat.com</managingEditor>
  <webMaster>webmaster@linuxformat.com</webMaster>
  <pubDate>Thu May 23, 2013 8:18 am</pubDate>
  <lastBuildDate>Thu May 23, 2013 8:18 am</lastBuildDate>
  <docs>http://backend.userland.com/rss</docs>
  <generator>phpBB2 RSS Syndication Mod by Lucas</generator>
  <ttl>1</ttl>

  <image>
    <title>Linux Format forums</title>
    <url></url>
    <link>http://www.linuxformat.com/forums/</link>
    <description>Help, discussion, magazine feedback and more</description>
  </image>

                                      <item>
                                        <title>RE: iptables -C check command</title>
                                        <link>http://www.linuxformat.com/forums/viewtopic.php?p=2176#2176</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://www.linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=133'&gt;jjmac&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Mon May 23, 2005 11:32 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      &amp;gt;&amp;gt;&lt;br /&gt;
Can anybody confirm for me - is there anything that has replaced the iptables check command -C? I'm a newbie to iptables &amp;amp; am wanting to test FORWARD rules allowing access from networks that I have no access to.&lt;br /&gt;
&amp;gt;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
There dosen't appear to be a dedecated check facility listed in the man page. But it sounds like it should have. Using some sought of loop-back facility i would think.&lt;br /&gt;
&lt;br /&gt;
But i'm not sure if i'm following you with your reason.. I though a 'FORWARD'rule would be for passing on packets to another location. As would be used by a gateway. If you want to govern the access condition of other networks, wouldn't that involve the 'INPUT' chain first. And then the FORWARD target, depending on the kind of match. Or do you mean just passing on networks that you don't want to access your network ... if they should come by ???&lt;br /&gt;
&lt;br /&gt;
I'd create a seperate chain for rule testing though. And insert an initial rule to jump to it in the FORWARD chain. Then you could just remove/insert that one rule to include the whole set in the testing chain.&lt;br /&gt;
&lt;br /&gt;
I suppose, if you set it up for a specific external box/network, and use that as a specific rule match, that could pass for a testing method. You would just need a someone with their own network set up that they could lend.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
jm&lt;br /&gt;
&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Code:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;code&quot;&gt;&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-&amp;#58;-&amp;nbsp; If the system is the answer, then the question &lt;br /&gt;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; must have been really stupid&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; -&amp;#58;-&lt;br /&gt;
&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;span class=&quot;postbody&quot;&gt;</description>
                                        <comments>http://www.linuxformat.com/forums/viewtopic.php?p=2176#2176</comments>
                                        <author>jjmac</author>
                                        <pubDate>Mon May 23, 2005 11:32 am</pubDate>
                                        <guid isPermaLink="true">http://www.linuxformat.com/forums/viewtopic.php?p=2176#2176</guid>
                                      </item>
                                      <item>
                                        <title>RE: iptables -C check command</title>
                                        <link>http://www.linuxformat.com/forums/viewtopic.php?p=2166#2166</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://www.linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=610'&gt;smita034&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Mon May 23, 2005 10:00 am&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      You can list all the current rules using iptables -L it will split them into groups and output it quite neatly, as for testing it, only way i know of is to use it....&lt;br /&gt;
&lt;br /&gt;
Hope that helps a little</description>
                                        <comments>http://www.linuxformat.com/forums/viewtopic.php?p=2166#2166</comments>
                                        <author>smita034</author>
                                        <pubDate>Mon May 23, 2005 10:00 am</pubDate>
                                        <guid isPermaLink="true">http://www.linuxformat.com/forums/viewtopic.php?p=2166#2166</guid>
                                      </item>
                                      <item>
                                        <title>iptables -C check command</title>
                                        <link>http://www.linuxformat.com/forums/viewtopic.php?p=2133#2133</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://www.linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=-1'&gt;Anonymous&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Sun May 22, 2005 4:06 pm&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      Hi&lt;br /&gt;
&lt;br /&gt;
Can anybody confirm for me - is there anything that has replaced the iptables check command -C?  I'm a newbie to iptables &amp;amp; am wanting to test FORWARD rules allowing access from networks that I have no access to.  &lt;br /&gt;
&lt;br /&gt;
Anbody got any ideas how I would test this if there's no replacement for -C??&lt;br /&gt;
&lt;br /&gt;
Much appreciated&lt;br /&gt;
&lt;br /&gt;
Stuibby</description>
                                        <comments>http://www.linuxformat.com/forums/viewtopic.php?p=2133#2133</comments>
                                        <author>Anonymous</author>
                                        <pubDate>Sun May 22, 2005 4:06 pm</pubDate>
                                        <guid isPermaLink="true">http://www.linuxformat.com/forums/viewtopic.php?p=2133#2133</guid>
                                      </item></channel></rss>