sudo addgroup -gid 2000 nointernet
sudo usermod -a -G nointernet fabio
/sbin/iptables -N LOGDROP
/sbin/iptables -A LOGDROP -j LOG
/sbin/iptables -A LOGDROP -j DROP
/sbin/iptables -A OUTPUT -m owner --gid-owner 2000 ! -d 127.0.0.1 -j LOGDROP
sg nointernet <applicationName>
sudo usermod -a -G nointernet fabio
/sbin/iptables -N LOGDROP
/sbin/iptables -A LOGDROP -j LOG
/sbin/iptables -A LOGDROP -j DROP
/sbin/iptables -A OUTPUT -m owner --gid-owner 2000 ! -d 127.0.0.1 -j LOGDROP
sg nointernet <applicationName>
No comments:
Post a Comment