iptables: separate clients from each other

Posted by Florian Lagg on Super User See other posts from Super User or by Florian Lagg
Published on 2010-05-18T16:36:51Z Indexed on 2010/05/18 16:41 UTC
Read the original article Hit count: 215

Filed under:
|
|

Hello, is there a way to separate clients in a subnet so that they cannot reach each other?

The infrastructure currently looks like this:

  • 192.168.0.1/24 Gateway, a CentOS box with iptables.
  • 192.168.0.10-20 Some clients which may reach each other
  • 192.168.0.30 A single client which
    • should not be able to reach the hosts 192.168.0.10-20
    • should be able to reach the gateway and the internet

I don't know if it is possible, maybe you could give me your ideas how it could be done. I cannot influence the machine 192.168.0.30 because it is a virtual machine I want to rent to someone. Thanks.

© Super User or respective owner

Related posts about subnet

Related posts about iptables