LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 03-31-2003, 09:44 PM   #1
nelse23
LQ Newbie
 
Registered: Jan 2003
Posts: 23

Rep: Reputation: 15
Redhat 8.0 Firewall


I'm trying to use IP Masquradeing to connect an older computer to Redhat 8.0. I haven't been able to allow it to connect.

I've noticed that if I attempt to change the security level it doesn't seem to work.

It's usually set to High.

I try to change it to Medium and allow different incoming connections.

I save it, but when I go back to it later, it's set back to High.

Anyone have any ideas on this?
 
Old 03-31-2003, 09:47 PM   #2
bentz
Member
 
Registered: Mar 2003
Distribution: Fedora, Mac OSX
Posts: 362

Rep: Reputation: 30
For RedHat, the output of
/etc/rc.d/init.d/iptables status
--or--
/etc/rc.d/init.d/ipchains status
would be helpful here. It will display all your firewall rules, and hopefully someone will be able to answer your questions.
 
Old 03-31-2003, 09:59 PM   #3
Crashed_Again
Senior Member
 
Registered: Dec 2002
Location: Atlantic City, NJ
Distribution: Ubuntu & Arch
Posts: 3,503

Rep: Reputation: 57
The GUI for Firewall Settings just doesn't make any sense to me. Just like you said, it seems that when you make a change and then go back nothing changes. Just use the commands that bentz said to see your current firewall rules or do:

iptables -L
 
Old 03-31-2003, 10:28 PM   #4
bentz
Member
 
Registered: Mar 2003
Distribution: Fedora, Mac OSX
Posts: 362

Rep: Reputation: 30
I'm not at all familiar with the GUI tools... But: If you make rule changes, you will need to save them so that they survive a reboot. Use the command 'iptables-save > /etc/sysconfig/iptables'. This will write your current ruleset to a configuration file, which will be read upon the next reboot or '/etc/rc.d/init.d/iptables start'. There is also an iptables-restore, but I'm too lazy to RTFM for that one.
 
Old 03-31-2003, 10:57 PM   #5
green_dragon37
Member
 
Registered: Oct 2002
Location: Lower Alabama
Distribution: Slackware, OpenBSD 3.9
Posts: 344

Rep: Reputation: 31
Get Guarddog. I did, works wonderfully.

http://freshmeat.net/projects/guarddog/
 
Old 04-01-2003, 06:24 AM   #6
nelse23
LQ Newbie
 
Registered: Jan 2003
Posts: 23

Original Poster
Rep: Reputation: 15
I'll give these a try. Thanks for your help.
 
Old 04-01-2003, 08:16 AM   #7
nelse23
LQ Newbie
 
Registered: Jan 2003
Posts: 23

Original Poster
Rep: Reputation: 15
I ran iptables status and here's what I got:

Table: nat
Chain PREROUTING (policy ACCEPT)
target prot opt source destination

Chain POSTROUTING (policy ACCEPT)
target prot opt source destination
MASQUERADE all -- anywhere anywhere

Chain OUTPUT (policy ACCEPT)
target prot opt source destination
Table: filter
Chain INPUT (policy ACCEPT)
target prot opt source destination

Chain FORWARD (policy ACCEPT)
target prot opt source destination
ACCEPT all -- anywhere anywhere state RELATED,ESTABL
ISHED
ACCEPT all -- anywhere anywhere
LOG all -- anywhere anywhere LOG level warning

Chain OUTPUT (policy ACCEPT)
target prot opt source destination

Chain RH-Lokkit-0-50-INPUT (0 references)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp dpt:http flags:S
YN,RST,ACK/SYN
ACCEPT tcp -- anywhere anywhere tcp dpt:ftp flags:SY
N,RST,ACK/SYN
ACCEPT tcp -- anywhere anywhere tcp dpt:ssh flags:SY
N,RST,ACK/SYN
ACCEPT tcp -- anywhere anywhere tcp dpt:smtp flags:S
YN,RST,ACK/SYN
ACCEPT tcp -- anywhere anywhere tcp dpt:telnet flags
:SYN,RST,ACK/SYN
ACCEPT all -- anywhere anywhere
ACCEPT all -- anywhere anywhere
ACCEPT udp -- ns02.toresd01.pa.comcast.net anywhere udp spt:dom
ain
ACCEPT udp -- ns01.toresd01.pa.comcast.net anywhere udp spt:dom
ain
REJECT tcp -- anywhere anywhere tcp flags:SYN,RST,AC
K/SYN reject-with icmp-port-unreachable
REJECT udp -- anywhere anywhere udp reject-with icmp
-port-unreachable

I'm not sure if everything is alright here.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Disable Firewall in Redhat 9 PacMansRancor Linux - General 3 09-26-2005 08:29 PM
Redhat firewall belorion Linux - Software 1 08-08-2004 08:43 PM
Firewall in Redhat 9 coolest Linux - Security 10 09-14-2003 06:30 PM
RedHat 8.0 Firewall jonathanw Linux - Newbie 3 07-31-2003 10:10 AM
redhat 7.3 firewall i_is_cat Linux - Security 14 06-22-2003 04:30 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 04:52 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration