LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-27-2009, 11:56 AM   #1
zivota
Member
 
Registered: May 2005
Distribution: CENTOS
Posts: 91

Rep: Reputation: 15
IPTABLES don't come back after reboot


Hi,

I encountered this problem several times so far.

I have two linux boxes (centos) acting as firewall-routers between two networks. Each works on it's own and networks are not related. Everything is ok until I reboot machine but when it comes back, machine doesn't route between networks anymore. After I restart iptables service and re-run my rules it's fine again.

After each change I do

#service iptables save

so I assume that iptables are supposes to re-read rules after machine boots, but .. it doesn't.


Centos 4.7 and 5.2

Anybody had a similar problem so far?
 
Old 02-27-2009, 12:00 PM   #2
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by zivota View Post
Hi,

I encountered this problem several times so far.

I have two linux boxes (centos) acting as firewall-routers between two networks. Each works on it's own and networks are not related. Everything is ok until I reboot machine but when it comes back, machine doesn't route between networks anymore. After I restart iptables service and re-run my rules it's fine again.

After each change I do

#service iptables save

so I assume that iptables are supposes to re-read rules after machine boots, but .. it doesn't.


Centos 4.7 and 5.2

Anybody had a similar problem so far?
What does chkconfig show?
Code:
chkconfig --list
 
Old 02-27-2009, 12:55 PM   #3
zivota
Member
 
Registered: May 2005
Distribution: CENTOS
Posts: 91

Original Poster
Rep: Reputation: 15
chkconfig is fine

# chkconfig --list iptables
iptables 0 off 1 off 2 on 3 on 4 on 5 on 6 off

While posting this line I got some stupid message about icons ... so I just removed colons.
 
Old 02-27-2009, 12:59 PM   #4
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Is IP forwarding enabled when the system starts?

Or does that too get reset like with the iptables configuration?

PS: There's an option to disable smilies when you post.
 
Old 02-27-2009, 01:30 PM   #5
zivota
Member
 
Registered: May 2005
Distribution: CENTOS
Posts: 91

Original Poster
Rep: Reputation: 15
Quote:
Originally Posted by win32sux View Post
Is IP forwarding enabled when the system starts?

Or does that too get reset like with the iptables configuration?

PS: There's an option to disable smilies when you post.
/proc/sys/net/ipv4/ip_forward is 0 when machine boots but it's activated once you execute iptables scrips ... hmmmm Win32sux you opened my eyes.

Since I have that in my script, when machine boots it applies only rules saved before, but not kernel parameters?! Am I right?
 
Old 02-27-2009, 02:09 PM   #6
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by zivota View Post
/proc/sys/net/ipv4/ip_forward is 0 when machine boots but it's activated once you execute iptables scrips ... hmmmm Win32sux you opened my eyes.

Since I have that in my script, when machine boots it applies only rules saved before, but not kernel parameters?! Am I right?
Correct, iptables has nothing to do with it.

If you want it to stick, either add an echo to rc.local (or whatever) or make the appropriate edit to /etc/sysctl.conf.
 
Old 02-27-2009, 02:14 PM   #7
zivota
Member
 
Registered: May 2005
Distribution: CENTOS
Posts: 91

Original Poster
Rep: Reputation: 15
Quote:
Originally Posted by win32sux View Post
Correct, iptables has nothing to do with it.

If you want it to stick, either add an echo to rc.local (or whatever) or make the appropriate edit to /etc/sysctl.conf.
I just did correct /etc/sysctl.conf.

Thank you for your help
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
troubleshoot: my server goes down. Comes back up after reboot twlilinux Linux - Server 4 08-26-2008 06:18 PM
iptables firewall falls back to default after reboot lx3000 Linux - Security 8 03-31-2006 04:02 PM
monitor goes black, will not respond. have to reboot to get back in pjbii Slackware 1 03-13-2005 11:37 AM
Venting : Back From ReBoot-HELL.... Megamieuwsel General 7 10-02-2004 06:19 AM
Server fails to reboot when power is back on edmunthali Red Hat 0 03-07-2004 01:35 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:02 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration