Skip to content

My 'temporary' iptables rule lasted three years

General Discussion by MARIA3 22 replies 3.2K views
#1

Hello friends, I want to share funny story. I was cleaning old server and found iptables rule from 2023. DROP all traffic from country block, I make for temporary test. Three years it was there! I wonder why nobody complain... then I check logs. It was North Korea IP range 😊 Nobody try connect from there ever. Server up and running fine all time. Regards

siesta first, deploy later
#2

Haha thats gold. How much u pay for that server? I got a $8/year deal at nodeharbor once, no iptables needed teh firewall was broken anyway

1 #3

Legacy IP geofiltering is a dead end. With 340 undecillion addresses in the IPv6 address space, your temporary rule would have required 0000:0000:0000:0000:0000:0000:0000:0000 to ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff just to match one country. Dual-stack would not have saved you. NAT is the real enemy here, not North Korea

#4

Just use nftables. Skill issue. Also if you had users in north korea you have bigger problems than iptables 🐧

oops: 0000 [#1] SMP
#5

This is EXACTLY why you need automated rule auditing. What if it had been a real customer region? What if the rule had been ACCEPT instead of DROP and you leaked internal services? fail2ban would have logged this properly. You got lucky. Never trust "temporary" anything on production! 👀

airgapped, encrypted, faraday'd, still worried
6 #6

MARIA3 said:
Temporary test. Three years it was there
This happen to me also. I block russia since 2021 for test and forget. My server down for them but I dont know since nobody tell me. Important lesson: write notes. I use since two years now no problem

#7

Three years. The young people and their cloud nonsense. They think a rule is temporary because they named it so. In my day we had change logs. Paper ones. Signed by three people. Now a DROP sits for a thousand days and they laugh. I weep and smile together...

#8

North Korea logs stay empty. Best firewall.

IPv4, IRC, and irssi — fight me
#9

Tanie serwery to moja pasja, ale tanie geofiltry to głupota. I use Hetzner in Falkenstein, they have good firewall panel. You click, you forget, you pay. But at least you see what you block.

3 #10

playersofia said:
NAT is the real enemy here
NAT is not the enemy, state tables are. I run btrfs on my firewall logs and you should too. Compression ratio on empty North Korean logs is spectacular, by the way.

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft