LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 05-17-2003, 02:45 AM   #1
renato167
LQ Newbie
 
Registered: May 2003
Posts: 16

Rep: Reputation: 0
Talking shorewall = frustration


need help please!

newbie here.

trying to build my first linux firewall w/ shorewall

redhat 8.0

latest version of shorewall firewall

eth0 connected to cable modem (dhcp)

eth1 masquerade 192.168.1.254

two-interface sample downloaded from shorewall and files
copied to /etc/shorewall directory

/sbin/shorewall start

i get

"connection refused when accessing www.google.com"

or something to that effect.

definitely "connection refused'

i have to /sbin/shorewall clear to get access to the Internet.


any assistance from the board would be appreciated.
 
Old 05-17-2003, 02:57 PM   #2
Robert0380
LQ Guru
 
Registered: Apr 2002
Location: Atlanta
Distribution: Gentoo
Posts: 1,280

Rep: Reputation: 47
i always suggest using iptables for firewalling:


#!/bin/bash
IPTABLES="/sbin/iptables"
NETIFACE="eth0"
LANIFACE="eth1"
LAN_IP="192.168.1.254" ##### FOR YOU ITS 192.168.1.254
www="80" ### http port
XPORT="6000" ### X11 open port
SSH="22" #### ssh port

### FLUSH TABLES ###
$IPTABLES -F
$IPTABLES -t nat -F

### SET POLICIES ###
echo Setting Firewall Policies
$IPTABLES -P INPUT DROP #### PUT SYSTEM ON LOCK DOWN ###
$IPTABLES -P FORWARD DROP #### ROUTING LOCK DOWN
$IPTABLES -P OUTPUT ACCEPT #### ALLOW ALL OUTGOING

### ALLOW established INTERNET CONNECTIONS ###
$IPTABLES -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT

### ALLOW CONNECTIONS ON PORT 22(SSH) ###
$IPTABLES -A INPUT -p tcp --dport $SSH -j ACCEPT

### ALLOW http CONNECTIONS ###
$IPTABLES -A INPUT -p tcp --dport $www -j ACCEPT

### ALLOW PING ###
$IPTABLES -A INPUT -p icmp -j ACCEPT

### TRUST THE LAN COMPUTER ###
$IPTABLES -A INPUT -s LAN_IP -j ACCEPT

### MASQUERADING ###
$IPTABLES -t nat -A POSTROUTING -s $LAN_IP -o $NETIFACE -j MASQUERADE

echo Done



As you can see by the comments, my box only allows incomming connections on port 80, 22 and any icmp requests ( i wanted the box to be pingable). You can take this, copy it to a file called firewall.sh, and run it:

# sh firewall.sh

if you decided to try this and you get errors, post again and i'll help you fix em, i just went through this and edited it about 4 or 5 times in this post so it might have some errors. You can check your firewall rules by typing the following:

#iptables -L
and
#iptables -t nat -L

and you can delete all the rules (if something isnt working and u just want the firewall down)

#iptables -F
#iptables -t nat -F

if just typing iptables doesnt work try /sbin/iptables

Last edited by Robert0380; 05-17-2003 at 03:17 PM.
 
Old 05-18-2003, 11:01 PM   #3
renato167
LQ Newbie
 
Registered: May 2003
Posts: 16

Original Poster
Rep: Reputation: 0
Smile whoooo hooooo

thanks


everything is working just fine.

again, many thanks.


renato
 
Old 05-19-2003, 12:25 AM   #4
Robert0380
LQ Guru
 
Registered: Apr 2002
Location: Atlanta
Distribution: Gentoo
Posts: 1,280

Rep: Reputation: 47
did you actually use iptables or did you get shorewall working?
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
shorewall config question with /etc/shorewall/rules peter72 Linux - Networking 3 01-01-2007 09:33 PM
Ipod frustration. drbroccoli Linux - Hardware 1 07-27-2005 02:49 PM
The frustration of nameservers being down jobokoth Linux - General 3 08-20-2003 04:22 AM
Samba frustration debest Linux - Networking 5 08-08-2003 11:29 PM
Frustration with Mandrake 9.1 frkstein Linux - General 2 04-02-2003 07:09 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 12:14 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration