LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 03-20-2007, 09:12 PM   #1
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Rep: Reputation: 60
Strange Routing/Firewall Issue


I have a a VOIP PBX in a DMZ behind my firewall at home and I have been playing around with IPTABLES. I wanted certain ports like 80,443,5060-5065,and others to be open so that I can browse the net,have my VOIP phones work with my PBX and etc. Here is the strange part. From the CLI I can ping a domain via IP or name, download updates and install them via YUM and everythings works fine from the CLI. The minute I open up a web browser I cannot get to any website. I can see it making an attempt but I cannot get to any webpage for browsing! I can even dig umuc.edu or any other domain and get feedback! What could it be and can some one give me a sample iptable rule set for a SOHO DMZ setup?

Last edited by metallica1973; 03-20-2007 at 09:18 PM.
 
Old 03-21-2007, 04:38 AM   #2
aus9
LQ 5k Club
 
Registered: Oct 2003
Location: Western Australia
Distribution: Icewm
Posts: 5,842

Rep: Reputation: Disabled
how about port 53 for domain name server checks

not sure how you are using the net to post, heh heh

www.linuxhomenetworking.com

Last edited by aus9; 03-21-2007 at 04:43 AM.
 
Old 03-21-2007, 09:21 AM   #3
Quigi
Member
 
Registered: Mar 2003
Location: Cambridge, MA, USA
Distribution: Ubuntu (Dapper and Heron)
Posts: 377

Rep: Reputation: 31
Yes, it could be a DNS issue. Can you point your browser at a site by IP address (i.e., resolve the name manually outside of the browser)?
I've run tcpdump on port 53 (UDP, but you can leave that unspecified) to see DNS requests and replies. (The issue I had to debug was that my router sometimes didn't pass the replies back in.)
 
Old 03-22-2007, 02:12 PM   #4
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Original Poster
Rep: Reputation: 60
I cannot get to a website via http. I do not understand how I can ping a website the name, ex. linuxquestions.org or google.com via the CLI and get a reply and when I go to the browser nothing. If DNS was the issue then how am I able to get a reply via the CLI by name:

[example@test ~]$ ping google.com
PING google.com (64.233.167.99) 56(84) bytes of data.
64 bytes from py-in-f99.google.com (64.233.167.99): icmp_seq=1 ttl=235 time=44.8 ms
64 bytes from py-in-f99.google.com (64.233.167.99): icmp_seq=2 ttl=235 time=45.2 ms
64 bytes from py-in-f99.google.com (64.233.167.99): icmp_seq=3 ttl=235 time=45.3 ms

--- google.com ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 1999ms
rtt min/avg/max/mdev = 44.844/45.156/45.356/0.283 ms

I am have trouble believing that it is DNS!
 
Old 03-23-2007, 08:12 AM   #5
Quigi
Member
 
Registered: Mar 2003
Location: Cambridge, MA, USA
Distribution: Ubuntu (Dapper and Heron)
Posts: 377

Rep: Reputation: 31
Sounds like ping can resolve names no problem. To confirm that DNS is not the issue with the browser, you could paste http://64.233.167.99/ into the browser.

Quote:
I wanted certain ports like 80,443,5060-5065,and others to be open so that I can browse the net,have my VOIP phones work with my PBX and etc.
In the usual lingo, you only need ports 80 and 443 open (i.e., accepting connections from the internet) if you run a web server. They don't need to be "open" to browse the net. The typical iptables setup accepts any connection initiated from inside, and the reply packets from the website are allowed in because they're related to the connection established by your browser. That's not to say that other configurations aren't possible -- some companies limit what outgoing connections their employees may establish.
 
Old 03-26-2007, 09:37 PM   #6
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Original Poster
Rep: Reputation: 60
Ironically my main firewall went down and I ended up replacing the machine and rebuilding my firewall and all is fine. I used the same firewall script that was on the other firewall and made some adjustments and it works fine. I must have had something on the VOIP server that wasnt routing correctly. Many thanks!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Routing issue with two linux with firewall sajjad81 Linux - Networking 1 04-06-2007 05:41 PM
Routing or firewall issue svandena Linux - Networking 6 11-14-2006 09:34 AM
strange ip routing table props666999 Slackware 3 11-03-2004 10:58 AM
strange routing problem citro Linux - Networking 3 07-25-2003 05:58 AM
masquerading / routing /firewall issue? VultureCulture Linux - Networking 2 10-04-2002 11:47 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 07:38 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration