LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 09-14-2005, 01:35 PM   #1
Funky D
LQ Newbie
 
Registered: Oct 2004
Posts: 7

Rep: Reputation: 0
Firewall blocking some POP3 requests


Hi all,

Hopefully someone can point me in the right direction. I have our Mandrake MNF firewall set up so users can download their POP3 email from home. Well, within the past few months, users accessing the net via RoadRunner can no longer retreive their POP3 email from our server.

I checked the firewall and found the following in the log when the users were trying to connect:

Code:
CPE-12-345-67-89.wi.res.rr.com
3 Aug 29 13:58:48 00:00:00:09 Shorewall:rfc1918:DROP: eth1 tcp 12.345.67.89 CPE-12-345-67-89.wi.res.rr.com 65025 172.20.1.3 - 110 SYN
I can see that shorewall thinks the packet is coming from a private network. How could this be the case? Is there anything I can do to let this traffic through?

Thank you all for the time,

Paul
 
Old 09-14-2005, 05:42 PM   #2
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
Odd. I wonder if it's some sort of buggy routing. Can you get a tcpdump or something?
 
Old 09-22-2005, 03:14 PM   #3
Funky D
LQ Newbie
 
Registered: Oct 2004
Posts: 7

Original Poster
Rep: Reputation: 0
Thank you for the reply! After doing some more searching I've found that roadrunner is starting to use some addresses reserved by the iana. Should I just comment out the addresses from the /etc/shorewall/rfc1918 file, or is there a better solution?

Thanks again,

Paul
 
Old 09-23-2005, 11:35 AM   #4
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
Well, you could do that. I wouldn't.

I don't understand how roadrunner thinks they can just decide to use RFC 1918 addresses.

I realize this may not be a solution to your liking, but I would tell the users that their ISP is using a broken network. My firewall blocks 127.0.0.0/8, 10.0.0.0/8, 192.168.0.0/16, and 172.16.0.0/12 networks on the public interface, no questions about it. Too high risks of spoofing and the like.

Road runner should not be doing this and I am honestly surprised that upstream ISPs don't just block the traffic themselves.
 
Old 09-23-2005, 11:53 AM   #5
Funky D
LQ Newbie
 
Registered: Oct 2004
Posts: 7

Original Poster
Rep: Reputation: 0
Thanks again! The addresses they are using are within the 70.0.0.0/7 and 72.0.0.0/5 networks, which were both listed in the rcf1918 file. I didn't even know there was anything "reserved" about those addresses before finding them in that file, which is why I was so stumped in the first place!
 
Old 09-23-2005, 04:21 PM   #6
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
Upon closer inspection, the source IP in the log you posted appears to be 12.345.67.89, a perfectly valid IP address.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
firewall blocking internet k4zau Linux - Networking 1 09-24-2004 02:18 PM
blocking Web on firewall to use only squid mfeoli Linux - Networking 0 01-27-2004 10:04 AM
firewall traffic blocking help jaylee Linux - Security 8 06-30-2003 10:44 AM
blocking DHCP requests jjfate Linux - Networking 4 06-20-2003 01:49 PM
Firewall not blocking ports... bfloeagle Linux - Security 9 05-20-2003 02:53 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 01:49 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration