public inbox for gentoo-user@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-user] modifying iptables: how can I prevent locking me out?
@ 2011-01-24 18:47 Jarry
  2011-01-24 18:59 ` Mark Knecht
  2011-01-24 21:40 ` J. Roeleveld
  0 siblings, 2 replies; 16+ messages in thread
From: Jarry @ 2011-01-24 18:47 UTC (permalink / raw
  To: gentoo-user

Hi,

I have to change rather complex iptables rules on server
and I do not want to lock me out as this server is about
50 miles away. So how should I do it?

I can back up the old rules by running:
/etc/init.d/iptables save
and it will be saved to /var/lib/iptables/rules-save
(some strange format starting with number like [536:119208])

I prepared a script with new (modified) iptables-rules,
which I will run in bash. But in case I screw something,
how could I force netfilter to load old saved rules,
if I for whatever reason do not connect to server (ssh)?

Or can I load new iptables-rules for certain time, and
then force netfilter to load back the old rules again?

Jarry

-- 
_______________________________________________________________
This mailbox accepts e-mails only from selected mailing-lists!
Everything else is considered to be spam and therefore deleted.



^ permalink raw reply	[flat|nested] 16+ messages in thread

end of thread, other threads:[~2011-01-31 22:11 UTC | newest]

Thread overview: 16+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-01-24 18:47 [gentoo-user] modifying iptables: how can I prevent locking me out? Jarry
2011-01-24 18:59 ` Mark Knecht
2011-01-24 19:06   ` kashani
2011-01-24 19:16     ` Mark Knecht
2011-01-24 21:08   ` Manuel Klemenz
2011-01-24 21:50   ` Neil Bothwick
2011-01-24 22:14     ` Mark Knecht
2011-01-24 22:16       ` Mark Knecht
2011-01-25 10:25         ` Neil Bothwick
2011-01-25 22:57           ` Mick
2011-01-24 22:28       ` Alan McKinnon
2011-01-25 10:19         ` Neil Bothwick
2011-01-24 22:26     ` Alex Schuster
2011-01-31 21:20     ` Jarry
2011-01-24 21:40 ` J. Roeleveld
2011-01-24 22:31   ` Alan McKinnon

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox