LinuxQuestions.org
Latest LQ Deal: Linux Power User Bundle
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 04-28-2014, 05:56 AM   #1
kbnuts
Member
 
Registered: Apr 2014
Posts: 45

Rep: Reputation: Disabled
SL6 iptables config issue.


Hi guys, I'm pretty new to iptables so I got a couple of KVM machines and set up an ftp server. I used system-config-firewall-tui to set up the ftp port.

Bang.. works, the other machine can connect, job is good.

So I look at the changes to /etc/sysconfig/iptables and see that the config line is the same as the ssh one but for the ftp port of 21.

I take a copy of the file for reference

I take the rule out using system-config-firewall-tui and sure enough it's removed.

Then I put the rule in manually using vi (to make sure I did a yyp to copy the exact line then changed it to 21)

I restart iptables then check ising iptables -L and it reports that the ftp port is open.

However my other machine can't connect. I repeat this a few times and it appears that the rule works fine when done in system-config-firewall-tui but never when I've manually altered the file even though it reports as open. I made sure it was in the right place, directly below the ssh rule.

I also did a diff on the manually altered file and the one altered by the interface and they were identical.

Is there something I'm missing??

--
TL;DR version:

my iptables rule seems to work when set in the tui interface but not when manually editing the file. This is on Scientific Linux 6.5
 
Old 04-28-2014, 02:39 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,331
Blog Entries: 55

Rep: Reputation: 3529Reputation: 3529Reputation: 3529Reputation: 3529Reputation: 3529Reputation: 3529Reputation: 3529Reputation: 3529Reputation: 3529Reputation: 3529Reputation: 3529
- the iptables binary is the interface to the kernel part called Netfilter and no user interface shall interfere with using it that way,
- active FTP requires the control (TCP/21) and the data (TCP/20) port,
- the easiest way to debug iptables rules is to use "-j LOG" rules right before the actual rule,
- and I don't know about others but I'd rather see the actual rule set as in 'iptables-save' output.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
iptables packet filtering issue ? How iptables working. pradiptart Linux - Networking 3 02-13-2014 02:16 AM
Sending Signals from one program to several others in C/C++ on SL6.0 jlabbesstl Linux - Software 2 08-17-2011 11:19 AM
Mouse keeps freezing on SL6? szboardstretcher Linux - Software 1 07-26-2011 08:41 AM
[SOLVED] Slackware router: lan eth1 works, lan eth2 doesnt! Iptables config issue slugman Linux - Networking 2 06-21-2011 02:37 AM
possible samba config problem or network config issue? rruffin Linux - Networking 3 06-03-2003 05:04 PM


All times are GMT -5. The time now is 06:50 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration