Quote:
Originally Posted by amolredhat
Post output of below commands:-
# iptables -L
# sestatus
And how did you verified FW configuration ? Post rules.
|
Below is the result for iptables -L:
Chain INPUT (policy ACCEPT)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp dpt:ftp-data flags:FIN,SYN,RST,ACK/SYN
ACCEPT tcp -- anywhere anywhere tcp dpt:scientia-ssdb flags:FIN,SYN,RST,ACK/SYN
RH-Firewall-1-INPUT all -- anywhere anywhere
Chain FORWARD (policy ACCEPT)
target prot opt source destination
RH-Firewall-1-INPUT all -- anywhere anywhere
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
Chain RH-Firewall-1-INPUT (2 references)
target prot opt source destination
ACCEPT all -- anywhere anywhere
ACCEPT icmp -- anywhere anywhere icmp any
ACCEPT esp -- anywhere anywhere
ACCEPT ah -- anywhere anywhere
ACCEPT udp -- anywhere 224.0.0.251 udp dpt:mdns
ACCEPT udp -- anywhere anywhere udp dpt:ipp
ACCEPT tcp -- anywhere anywhere tcp dpt:ipp
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT tcp -- anywhere anywhere state NEW tcp dpt:ssh
ACCEPT udp -- anywhere anywhere state NEW udp dpt:xdmcp
ACCEPT tcp -- anywhere anywhere state NEW tcp dpt:ftp-data
ACCEPT tcp -- anywhere anywhere state NEW tcp dpt:scientia-ssdb
REJECT all -- anywhere anywhere reject-with icmp-host-prohibited
ACCEPT tcp -- anywhere anywhere state NEW,ESTABLISHED tcp dpt:ftp-data
ACCEPT tcp -- anywhere anywhere state NEW,RELATED,ESTABLISHED tcp dpt:ftp-data
ACCEPT tcp -- anywhere anywhere state NEW,ESTABLISHED tcp dpt:6001
ACCEPT tcp -- anywhere anywhere state NEW,ESTABLISHED tcp dpt:x11-ssh-offset
ACCEPT tcp -- anywhere anywhere state NEW,ESTABLISHED tcp dpt:6009
ACCEPT tcp -- anywhere anywhere state NEW,ESTABLISHED tcp dpt:6008
ACCEPT tcp -- anywhere anywhere state NEW,ESTABLISHED tcp dpt:6007
ACCEPT tcp -- anywhere anywhere state NEW,ESTABLISHED tcp dpt:6006
ACCEPT tcp -- anywhere anywhere state NEW,ESTABLISHED tcp dpt:6005
ACCEPT tcp -- anywhere anywhere state NEW,ESTABLISHED tcp dpt:6004
ACCEPT tcp -- anywhere anywhere state NEW,ESTABLISHED tcp dpt:6003
ACCEPT tcp -- anywhere anywhere state NEW,ESTABLISHED tcp dpt:6002
ACCEPT tcp -- anywhere anywhere state NEW,ESTABLISHED tcp dpt:6001
I have disabled selinux