Operasi pada Iptables Parameter Iptables Contoh Penggunaan Iptables

6 8 p olicies firewa ll. Di DMZ da p a t dile ta kka n la ya na n-la ya na n we b da n FTP ya ng m e m p e rb o le h k a n p e n g g u n a lu a r u n tu k m e nga ks e s s e rvis te rs e but. De nga n c a ra ini a ks e s da ri lua r ha nya a ka n dia ra hka n p a da s a tu s e gm e n DMZ s a ja da n ja ringa n da la m tida k bole h dia ks e s da ri lua r.

4.3 IPTables

Da la m ip ta bles a da tiga la bel uta m a , ya itu: INPUT : p a c ke t da ta ya ng m a suk da ri inte rfa c e kita OUTPUT : p a c ke t da ta ya ng ke lua r da ri inte rfa c e kita F O RWARD : p a c ke t da ta ya ng m e n u m p a n g u n tu k lewa t PAKET MASUK KEPUTUSAN ROUTING FORWARD PAKET KELUAR INPUT PROSES LOKAL OUTPUT Gam bar 4 .3 A lg oritm a k ep u tu s an rou tin g

4.3.1 Operasi pada Iptables

Be rikut ini a da la h op e ra si da la m Ip ta ble s: Tabel op eras i p ad a Ip tables Ope ras i Ops i Me m bua t c ha in ba ru -N 6 9 Me n g h a p u s c h a in k o s o n g -X Me ruba h a tura n da ri s ua tu c ha in -P Me liha t da fta r rule s -L Me n g h a p u s s e lu ru h ru le s -F Me nolka n hitunga n p a ke t da n byte da la m s ua tu c ha in -Z Me na m ba hka n rule ba ru p a da s ua tu c ha in -A Me m a s ukka n rule ba ru p a da p os is i te rte ntu da la m s ua tu c ha in -I Me ngga nti rule p a da s ua tu c ha in p a da p os is i te rte ntu -R Me ngha p us rule p a da c ha in te rte ntu da n p a da p os is i te rte ntu a ta u ya ng s e s ua i de nga n s p e s ifika s i -D

4.3.2 Parameter Iptables

Pa ra m e te r diguna ka n untuk m e m bua t a tura n le bih s p e s ifik bia s a nya diguna ka n p a da p e na m ba ha n, p e ngha p us a n, p e nyis ip a n, a ta u op e ra s i p e ngga ntia n. Tabel p aram eter p ad a Ip tables Parame te r Ops i Me n u n ju k k a n n a m a p ro to k o l ya n g d ig u n a k a n , b is a tcp , u d p , icm p , a ta u all -p Me n u n ju k k a n sou rce ad d res -s Me n u n ju k k a n d estin asi ad d ress -d -j Me nunjukka n inp ut da ri inte rfa c e -i Me n u n ju k k a n o u tp u t d a ri in te rfa c e -o 7 0

4.3.3 Contoh Penggunaan Iptables

Server B1:192.168.1.5 host A1: 192.168.2.5 host B2 :192.168.1.15 eth0 : 192.168.2.2 eth1 : 192.168.1.2 Gam bar 4 .4 S k en ario p enerap an ip tabels p ad a 2 netw ork Table Filter chain Forw ard Nam a S ubne t 1 9 2 .1 6 8 .1 .0 1 9 2 .1 6 8 .2 .0 1 9 2 .1 6 8 .1 .0 ACCEPT 1 9 2 .1 6 8 .2 .0 ACCEPT Pe rinta h Ip ta ble s a da la h s e ba ga i be rikut : iptables - -P INPUT DROP iptables - -P OUTPUT DROP iptables - -P FORWARD DROP Pe rinta h di a ta s dibua t a ga r s e luruh ke bija ka n p e rta m a p olic y u n tu k p e rta m a ka li a da la h DRO P. Pe rin ta h u n tu k m e le wa tk a n p a k e t d a ri n e two rk A k e n e two rk B m e la lui route r a da la h s e ba ga i be rikut : echo 1procsysnetipv4ip_forward iptables - -A FORWARD - -i eth0 - -o eth1 - -j ACCEPT iptables - -A FORWARD - -i eth1 - -o eth0 - -j ACCEPT Arti p e rinta h di a ta s be rturut-turut a da la h s e ba ga i be rikut: Me m a s tika n ba ris forwa rding dia ktifka n 7 1 Me m bua t a ga r ne twork A da p a t m e nya p a B Me m bua t a ga r ne twork B da p a t m e nya p a ne twork A Piliha n: J ika diinginka n A la ngs ung dija wa b ole h B ha nya u n tu k setia p ka li A m e la kuka n p a nggila n m a ka p e rinta hnya a da la h s e ba ga i b e rik u t: iptables - -A FORWARD - -i eth0 - -o eth1 - -j ACCEPT iptables - -A FORWARD - -i eth1 - -o - -m state - --state ESTABLISHED - - j ACCEPT J ika diinginka n a ga r ha nya host te rte ntu sa ja , ya itu B2 , ya ng da p a t m e nja wa b p a nggila n A1 m a ka g u n a k a n p e rin ta h b e rik u t: iptables - -A FORWARD - -i eth0 - -o eth1 - -j ACCEPT iptables - -A FORWARD - -i eth1 - -o eth0 - -s 192.168.1.6 - -d 192.168.2.5 - -m state - --state ESTABLISHED - -j ACCEPT Pe rinta h a ga r fire wa ll da p a t di-re m ote da ri B1 a da la h: iptables - -A INPUT - -p tcp - -s 192.168.1.5 -- -dport 22 - - j ACCEPT iptables - -A OUTPUT - -o eth1 - -m state - --state ESTABLISHED - -j ACCEPT

4.3.4 Kegunaan IPTables