by Sephiroth » March 24th, 2011, 1:48 am
You are correct, Tele. In my second picture, you see what I run now. It works fine, but I have not yet had the chance to plop the laptop into a wireless or wired DMZ and test it with "Shields Up!" or the like. I was only curious about allowing everything into lo because technically all data will eventually hit lo, right? I mean this web-page came in through wlan0, but Iceweasel runs on the local machine!
I'm marking this as solved because it works now. The solution was to drop everything incoming by default, and specify a set of rules for each interface manually. The only rule for the lo interface should be to accept. You can specify any rules you want for your other interfaces though.
Owyn: "This next one is a high elf sorceress or something, just get in close and stab her a few times, that'll teach her!"
Owyn: "I heard a rumor that you're an idiot. Is that true?"
Cicero: "Stab you, stab you, stab you!"
Psycho: "You sat in my swing, now I'm going to eat you!"
Psycho: "I think he's gonna' play xylophone with my spinal cord!"