LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - General
User Name
Password
Linux - General This Linux forum is for general Linux questions and discussion.
If it is Linux Related and doesn't seem to fit in any other forum then this is the place.

Notices


Reply
  Search this Thread
Old 06-17-2004, 01:30 PM   #1
kith
Member
 
Registered: Jun 2003
Location: Texas - Houston
Distribution: Gentoo/FreeBSD
Posts: 109

Rep: Reputation: 15
Quick Help :)


Hey guys, Im currently at work and us IT guys are kinda stumped on this one...


Our Apache machine runs Redhat 2.4.8, go figure I use Gentoo..FreeBSD ect ect.. but never used RetHat.. Then again its linux soo....

Anyway I was setting up samba with our winblows domain, no biggie right? Well all of the sudden SSH stoped working. From the RedHat machine I can SSH localhost (to my self) and ssh to various other public servers. However when I try and ssh from the winblows machines useing PuTTy the connection times out! I've even tryed forwarding the port just for testing purposes with no luck. Its not working internaly or externaly. I've checked the SSHD logs, and everything was fine. From the RadHat machine I ran ssh in verbose mode when connecting to localhost and it worked fine also. The only thing I can't do is connect from another machine, and I can't figure out why. I have not reinstalled SSH becuase I don't know how to use RPM's (heh funny eh?) Any Ideas???
 
Old 06-17-2004, 01:58 PM   #2
Dark_Helmet
Senior Member
 
Registered: Jan 2003
Posts: 2,786

Rep: Reputation: 374Reputation: 374Reputation: 374Reputation: 374
Did you make any changes to the firewall? Double-check and make sure it's not blocking the SSH port. Red Hat's lokkit utility annoys the ever-living crap out of me because it never remembers settings. Each time you run it, you must explicitly open every port you provide service on (rather than simply adding a new port to an existing config). So if you tried to poke a hole for samba, your access to SSH may have been overwritten.

Last edited by Dark_Helmet; 06-17-2004 at 02:00 PM.
 
Old 06-17-2004, 02:01 PM   #3
kith
Member
 
Registered: Jun 2003
Location: Texas - Houston
Distribution: Gentoo/FreeBSD
Posts: 109

Original Poster
Rep: Reputation: 15
lokit? I've not used it before. The only thing I did with anything public was log into our public router, which has nothing to do with the RadHat machine, can you be alittle more specific Also thanks for the quick reply
 
Old 06-17-2004, 02:10 PM   #4
Dark_Helmet
Senior Member
 
Registered: Jan 2003
Posts: 2,786

Rep: Reputation: 374Reputation: 374Reputation: 374Reputation: 374
A Red Hat box typically comes with a firewall installed (through iptables). Red Hat provides two means of accessing the firewall:

1. GUI: Main menu -> System Settings -> Security Level
2. command line: lokkit

Both allow you to specify a vague security level (high, medium, or none), and the ability to poke a hole for a limited number of services (web, ssh, telnet, ftp, dhcp, and smtp). It also allows you to open other ports by explicitly listing them below the checkboxes for web, ssh, etc.

Neither utility will provide you with the current configuration. To check your firewall, you'll need to issue iptables --list. It will list the rules in place for dropping packets. If you don't feel like interpreting those (somewhat cryptic) rules, you can run nmap from another box. It will tell you what ports are actively open on the machine.
 
Old 06-17-2004, 02:17 PM   #5
kith
Member
 
Registered: Jun 2003
Location: Texas - Houston
Distribution: Gentoo/FreeBSD
Posts: 109

Original Poster
Rep: Reputation: 15
Thanks for the quick reply again

However after checking the iptables -list and the GUI there is no mention of port 22 being denied, or accpted for that matter, so I don't think the problem lies there


Brb - someone fooked over there windows.
 
Old 06-17-2004, 02:27 PM   #6
Dark_Helmet
Senior Member
 
Registered: Jan 2003
Posts: 2,786

Rep: Reputation: 374Reputation: 374Reputation: 374Reputation: 374
My knowledge of iptables rule sets is somewhat limited, but I do know that a system has a default policy of accepting or rejecting a port. In other words either accept everything except ports A, B, C, and D, or reject everything except ports E, F, and G. For a secure system, it's the latter configuration. Would you mind posting the output of the iptables --list command?
 
Old 06-17-2004, 09:44 PM   #7
paeng16
Member
 
Registered: May 2004
Posts: 47

Rep: Reputation: 15
Hi,

This is most likely a firewall issue.

QUICK CHECK:
1) Flush all iptables rule.
2) Nmap port 22. This should have the status OPEN and not FILTERED.
3) Try to SSH.

If you can connect to ssh, change your firewall rules. I hope this help!

_______________________________________________
man is our friend my friend!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
just a quick hello Haley LinuxQuestions.org Member Intro 7 10-02-2004 03:10 PM
Quick Thank you dai Linux - Security 9 01-01-2004 04:20 AM
Really quick one finegan Linux - General 2 01-20-2002 06:52 PM
A quick one... c0c0deuz Linux - General 4 12-22-2001 01:51 PM
i need help quick please girlygirl Linux - Newbie 3 09-28-2001 08:10 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - General

All times are GMT -5. The time now is 11:59 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration