LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 05-19-2007, 01:16 PM   #1
298
LQ Newbie
 
Registered: Apr 2007
Distribution: Ubuntu & Debian
Posts: 16

Rep: Reputation: 0
some websites invisible after rerun iptables


I have a Debian Etch running as a firewall and router with a DSL modem in front of it and a few Ubuntus behind it. After rerunning the iptables script, the Ubuntus cannot connect to certain websites, but the Debian still can. Things get back to normal after restarting the PPP interface on the gateway.

Could this have anything to do with the connection tracking done by iptables? I tried clr_conns
on the Debian, but it didn't help. Is there any way to flush everything the firewall knows? Restarting the PPP connection isn't that good a solution because it will result in a new IP address which needs to be sent to DynDNS again, etc. Would be nice to have something simple that I could add to the iptables script.
 
Old 05-19-2007, 04:56 PM   #2
Mara
Moderator
 
Registered: Feb 2002
Location: Grenoble
Distribution: Debian
Posts: 9,696

Rep: Reputation: 232Reputation: 232Reputation: 232
Make sure the connections you have are closed after you restart iptables. Closing and opening a web browser should work, for instance, because iptables will get the whole new connection, so it should trace it correctly. After restarting iptables packets from existing connections may be dropped, because they will not be found in the connection cache.
 
Old 05-19-2007, 10:57 PM   #3
298
LQ Newbie
 
Registered: Apr 2007
Distribution: Ubuntu & Debian
Posts: 16

Original Poster
Rep: Reputation: 0
Restarting Firefox didn't help. The situation is the same. As I said, there are only some websites that are not reachable. My company's webmail (MS Exchange) and lists.digium.com are among them, this one here is not.

Other applications affected are the Weather Forecast Applet on my Gnome desktop and getmail running on my laptop. The latter is started by a cron job, so there shouldn't be any open connections. (It uses POP3 to connect to the same server that runs my company's webmail.) I just tried it again, it's repeatable. Running the iptables script breaks these things, poff/pon fixes them again.
 
Old 05-20-2007, 02:31 PM   #4
Mara
Moderator
 
Registered: Feb 2002
Location: Grenoble
Distribution: Debian
Posts: 9,696

Rep: Reputation: 232Reputation: 232Reputation: 232
As an experiment, restart the firewall and reset one of the clients. I guess it will then connect just fine. I'd also look in netstat result to see how many connections (and where) you have.

If it all doesn't help, it may be worth looking into the Debian firewall script. Do you have an option to log all dropped packets (just for debug purposes)? Looking into that log will show which rule drops your connections (if it's iptables fault at all). You may have enough debug at this time, so first look into the iptables log to see if it shows something interesting.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
using iptables how do i block file listing of websites? murphydims Linux - Security 4 04-26-2006 11:49 AM
iptables - cannot load certain websites Booster Linux - Networking 3 01-31-2006 10:52 PM
How to rerun network configuration script? pvv Debian 5 09-06-2005 02:12 PM
Want to rerun the network probe from install script rickh Debian 2 05-19-2005 09:57 AM
Iptables blocking certain websites?? Ikik Linux - Security 3 09-29-2003 02:39 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 01:40 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration