LinuxQuestions.org
Go Job Hunting at the LQ Job Marketplace
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices

Reply
 
LinkBack Search this Thread
Old 06-29-2004, 04:43 PM   #1
conn-fused
Member
 
Registered: Jun 2004
Posts: 124

Rep: Reputation: 15
Firewalling a ppp client under MAndrake 9.2


Using one computer, running Mandrake 9.2, with a ppp (dial-up) connection:

I had installed the guarddog firewall from an rpm, but recently removed it to try the firewall script I found at www dot malibyte dot net/iptables/scripts/fwscripts dot html.

I modified the conf file, and followed the instructions for starting up the firewall. Since I ran "/sbin/chkconfig --level 345 firewall.iptables on", I expect the firewall is running even if I've since rebooted.

PROBLEM 1: How can I test this? I'm worried because I didn't specify a way for my amule client to get through the firewall, but the program seems to work fine. Could I be unprotected? Could a different firewall - other than the script - be running? I know something has changed, because I can now use nmap to scan a friend's machine when under guarddog I could not.

PROBLEM 2: I tried a portscan courtesy of www dot grc dot com. It shows good results, as if all my ports are dropping all incoming packets. Why then does "nmap 127.0.0.1" tell me that ports 6000 (X) and 1720 (H323) are open? How do I close port 1720 if I don't want to use it?

PROBLEM 3: I've tried calling "/etc/rc.d/init.d/firewall.iptables start" when connected to the net (through ppp0). No errors are indicated, but this wrecks everything. For instance, Mozilla claims to be resolving websites, but they never open. Have I called the program a second time, or is firewall.iptables not my active firewall at all? How can I check?

PROBLEM 4: The firewalls.conf.iptables-generic file (see website in paragraph one) asks for an internal interface. I've commented this out, because I have no LAN behind the first Linux machine. Should there be something (ie 'lo') here?

Basically, I have a long ways to go before understanding firewalling, and material on the net seems aimed at firewalling a home LAN, not protecting a single machine (one that is both firewall and client). Any help/feedback will be appreciated. Thanks in advance.
 
Old 06-29-2004, 04:51 PM   #2
peter_robb
Moderator
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 47
iptables has it's own start "script" file in /etc/sysconfig/iptables
This file is loaded with /etc/init.d/iptables start

If you start another script, you need to flush the first one.. eg /etc/init.d/iptables stop
then start your other script..

Probably both scripts are biting each other..
from a command line do iptables-save to view the current rules

have a look at my favourite tutorial (with scripts)b at http://iptables-tutorial.frozentux.n...-tutorial.html
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Trackbacks are Off
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
How to link linux ppp client to windows ppp server? cyz Linux - Networking 2 12-11-2008 05:01 AM
Routing issue with VPN Client into PPP/Poptop loopy69 Linux - Networking 1 10-07-2004 08:48 AM
more reliable ppp dialup client than kppp? randomx Linux - Software 3 10-27-2003 09:45 PM
ppp server & client stand Linux - General 0 03-07-2003 10:11 PM
A network client can't ping a foreign host via a ppp connection Leandro Linux - Networking 1 11-15-2002 04:50 PM


All times are GMT -5. The time now is 02:48 PM.

Main Menu
 
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration