LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-04-2005, 03:48 PM   #1
johnnylo
LQ Newbie
 
Registered: Jan 2005
Posts: 5

Rep: Reputation: 0
Question FC3 firewall fails after running for a while.


Hi, I am running FC3 and use the GUI in GNome environment to configure the iptables.

It seems to me that my firewall need to be restarted after a day or two otherwise the port opened will be blocked again.

For example, I open 137, 138, 139 and 445 for my samba print server. I could print from my xp box, but if I try to ping the samba netbios name from xp box later, it can't find the box, indicating the ports I opened are not functioning.

And Same thing happen to port 80, but if I restart the firewall, everything goes fine again. so I suspect it is my linux firewall that cause it.


Any help is appreciate.
 
Old 01-04-2005, 04:15 PM   #2
saravkrish
Member
 
Registered: Mar 2004
Location: KY, USA
Distribution: Fedora Core 1
Posts: 190

Rep: Reputation: 30
Are you using firestarter? If yes, I think I know what is happening.

~Sarav
 
Old 01-04-2005, 04:24 PM   #3
johnnylo
LQ Newbie
 
Registered: Jan 2005
Posts: 5

Original Poster
Rep: Reputation: 0
I don't know. It is a GUI default in FC3. It is under applications -> system setting -> security level.

If firestarter is a third party software, probably I am not using it.
 
Old 01-04-2005, 05:42 PM   #4
saravkrish
Member
 
Registered: Mar 2004
Location: KY, USA
Distribution: Fedora Core 1
Posts: 190

Rep: Reputation: 30
Thats not firestarter. Btw, do try firestarter. Just google it. Its an opensource GUI firewall that is very user friendly and has more options.
 
Old 01-04-2005, 05:49 PM   #5
johnnylo
LQ Newbie
 
Registered: Jan 2005
Posts: 5

Original Poster
Rep: Reputation: 0
thanks, I will give it a try and update later.
 
Old 01-05-2005, 01:32 AM   #6
linuxles
Member
 
Registered: Mar 2004
Location: Austin, TX
Distribution: CentOS Fedora RHEL SLES Knoppix
Posts: 78

Rep: Reputation: 15
That's interesting. Haven't seen that problem.

When the machine is unreachable, is the network reachable from the machine?

Here's how you can check to see if the firewall is being changed somehow.

As root: run "iptables -L" and save the output in a file somewhere for later
reference. (ie: iptables -L > iptables-output1)

Then when the machine is unreachable. Run another "iptables -L" and compare
the output with the previous file. You might want to save the output to a different
file. (ie: iptables -L > iptables-output2). You can visually check for the changes
in the output or diff the two files to see the differences between them.
(ie: diff iptables-output1 iptables-output2)

If you see a difference, then something (possibly SeLinux) maybe disabling
or changing your settings... I don't know if SeLinux can or will do something
like this, it's just a thought.

/Les
 
Old 01-05-2005, 11:27 AM   #7
johnnylo
LQ Newbie
 
Registered: Jan 2005
Posts: 5

Original Poster
Rep: Reputation: 0
Quote:
Originally posted by saravkrish
Thats not firestarter. Btw, do try firestarter. Just google it. Its an opensource GUI firewall that is very user friendly and has more options.
I have installed firestarter last night. The installation is smooth and easy. I added all the port I need in the inbound policy and start testing. For the first 5 mins, I try to ping my netbios but no response. But then after that when I ping again, it worked. However, when I try to ping the netbios again this morning around 6:00 am, I got no response again.

So, it may be silly to ask, but do I need to turn off iptables service or the default security app from FC3 beforeI used firestarter?
 
Old 01-05-2005, 11:27 AM   #8
johnnylo
LQ Newbie
 
Registered: Jan 2005
Posts: 5

Original Poster
Rep: Reputation: 0
Quote:
Originally posted by linuxles
That's interesting. Haven't seen that problem.

When the machine is unreachable, is the network reachable from the machine?

Here's how you can check to see if the firewall is being changed somehow.

As root: run "iptables -L" and save the output in a file somewhere for later
reference. (ie: iptables -L > iptables-output1)

Then when the machine is unreachable. Run another "iptables -L" and compare
the output with the previous file. You might want to save the output to a different
file. (ie: iptables -L > iptables-output2). You can visually check for the changes
in the output or diff the two files to see the differences between them.
(ie: diff iptables-output1 iptables-output2)

If you see a difference, then something (possibly SeLinux) maybe disabling
or changing your settings... I don't know if SeLinux can or will do something
like this, it's just a thought.

/Les
Thanks, this is a good approach, I will give it a try.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
fc3: up2date fails pcandpc Linux - General 5 10-15-2005 04:50 PM
rc.firewall fails to start hubabuba Slackware 3 04-05-2005 05:17 AM
FC3 syslogd fails to start Chilli Burger Fedora - Installation 1 02-11-2005 08:22 PM
FC3 Kernel build fails at_work_with_jf Fedora 1 12-28-2004 04:54 AM
k3b 0.11.14 on FC3 fails in ripping one particular CD tanchoo1 Linux - Software 0 11-18-2004 02:20 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:55 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration