{"id":509,"date":"2010-05-24T16:12:06","date_gmt":"2010-05-24T23:12:06","guid":{"rendered":"http:\/\/sp2hari.com\/?p=509"},"modified":"2020-06-20T08:30:06","modified_gmt":"2020-06-20T08:30:06","slug":"security-settings-for-a-lamp-server-iptables-ssh","status":"publish","type":"post","link":"https:\/\/sp2hari.com\/index.php\/2010\/05\/24\/security-settings-for-a-lamp-server-iptables-ssh\/","title":{"rendered":"Security settings for a LAMP Server : Iptables"},"content":{"rendered":"<p>Security is the major concern for anyone hosting a website on the internet. These are the preliminary security settings to be performed to protect your server.<\/p>\n<p><strong>iptables<\/strong><br \/>\nOur server stack is LAMP. Hence iptables as the firewall is the most natural choice. The requirements are like<\/p>\n<p>1. Block everything except Ping, SSH, Apache, and SSL.<br \/>\n2. Enabled SSH only from the selected IP addresses.<\/p>\n<p>The following script takes care of all iptables settings. (Idea copied from <a href=\"http:\/\/serverfault.com\/questions\/84872\/iptables-ok-now-am-i-doing-it-right\">here<\/a>)<\/p>\n<p>Note: Please enter the command one by one. Make sure you replace IP1.IP2.IP3.IP4 with your own IP address.<\/p>\n<p><code># Establish a clean slate<br \/>\niptables -P INPUT ACCEPT<br \/>\niptables -P FORWARD ACCEPT<br \/>\niptables -P OUTPUT ACCEPT<br \/>\niptables -F # Flush all rules<br \/>\niptables -X # Delete all chains<br \/>\n# Disable routing. Drop packets if they reach the end of the chain.<br \/>\niptables -P FORWARD DROP<br \/>\n# Drop all packets with a bad state<br \/>\niptables -A INPUT -m state --state INVALID -j DROP<br \/>\n# Accept any packets that have something to do with ones we've sent on outbound<br \/>\niptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT<br \/>\n# Accept any packets coming or going on localhost (this can be very important)<br \/>\niptables -A INPUT -i lo -j ACCEPT<br \/>\n# Accept ICMP<br \/>\niptables -A INPUT -p icmp -j ACCEPT<br \/>\n# Allow ssh<br \/>\niptables -A INPUT -p tcp --dport 22 -j ACCEPT<br \/>\n# Allow httpd<br \/>\niptables -A INPUT -p tcp --dport 80 -j ACCEPT<br \/>\n# Allow mysql<br \/>\niptables -A INPUT -p tcp --dport 3306 -j ACCEPT<br \/>\n# Allow SSL<br \/>\niptables -A INPUT -p tcp --dport 443 -j ACCEPT<br \/>\n# Block all other traffic<br \/>\niptables -A INPUT -j DROP<br \/>\n<\/code><\/p>\n<p>I guess the above script should take care of the basic security issues. Hope it helps.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Security is the major concern for anyone hosting a website on the internet. These are the preliminary security settings to be performed to protect your server. iptables Our server stack is LAMP. Hence iptables as the firewall is the most natural choice. The requirements are like 1. Block everything except &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13],"tags":[],"class_list":["post-509","post","type-post","status-publish","format-standard","hentry","category-code"],"_links":{"self":[{"href":"https:\/\/sp2hari.com\/index.php\/wp-json\/wp\/v2\/posts\/509","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sp2hari.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sp2hari.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sp2hari.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sp2hari.com\/index.php\/wp-json\/wp\/v2\/comments?post=509"}],"version-history":[{"count":25,"href":"https:\/\/sp2hari.com\/index.php\/wp-json\/wp\/v2\/posts\/509\/revisions"}],"predecessor-version":[{"id":1355,"href":"https:\/\/sp2hari.com\/index.php\/wp-json\/wp\/v2\/posts\/509\/revisions\/1355"}],"wp:attachment":[{"href":"https:\/\/sp2hari.com\/index.php\/wp-json\/wp\/v2\/media?parent=509"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sp2hari.com\/index.php\/wp-json\/wp\/v2\/categories?post=509"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sp2hari.com\/index.php\/wp-json\/wp\/v2\/tags?post=509"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}