O'Reilly logo

CFEngine 3 Beginner's Guide by Rajneesh

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

Time for action - managing iptables with CFEngine

  1. You would already be using Iptables to filter access to various services, ports, and so on. One of the common filtering rules is allowing or restricting access to your web server server basis host IP addresses. The rules may look similar to the following:
    -A INPUT -s 152.168.2.0/24 -m state -state NEW -m tcp -p tcp dport 80 -j ACCEPT -A INPUT -s 152.168.4.0/24 -m state state NEW -m tcp -p tcp dport 80 -j ACCEPT -A INPUT -s 220.1.4.0/24 -m state -state NEW -m tcp -p tcp dport 80 -j ACCEPT -A INPUT -s 220.2.4.0/24 -m state -state NEW -m tcp -p tcp dport 80 -j ACCEPT -A INPUT -s 15.3.5.0/24 -m state -state NEW -m tcp -p tcp dport 80 -j ACCEPT -A INPUT -s 15.3.6.0/24 -m state -state NEW -m tcp -p tcp ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required