LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 03-04-2007, 09:54 AM   #1
cheesus
Member
 
Registered: Jan 2005
Location: Munich, Germany
Distribution: SuSE
Posts: 186

Rep: Reputation: 25
Question strange firewall behaviour - not just drops connection ?


Hello,

I have a fresh new SuSE 10.2 install.
I configured the firewall using control center and allowed only HTTPS.

Now when I do a port scan (e.g. http://probe.hackerwatch.org), I am
getting 443 open alright, but also 80 as open and many more
"This port is not being blocked, but there is no program currently accepting connections on this port."

Now when I telnet to my machine port 80 from internal, I get connected
to the apache. When I do that from the outside, I get a

Code:
Connected to xx.xx.xx.xx.
Escape character is '^]'.
Connection closed by foreign host.
So, is this 10.2 firewall accepting and closing connections instead
of just blocking/dropping them ?

I also checked the file /etc/sysconfig/SuSEfirewall2 and there really is
only 443 opened.

How can one explain that ? And yes, the firewall is working, because
I could not connect in on 443 before I opened that...

Any ideas anyone ? Cheers, Tom.
 
Old 03-04-2007, 11:47 AM   #2
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
First, I'm sure the URL you specified for port scanning is fine, but when I visited just now they were down for maintenance... Instead try something that is commonly used like grc.com - shield's up. Better yet, scan your box using nmap from another machine on the same network where the web service is supposed to be listening.

Second, if grc.com or your nmap scan gives the same results, then post your packet filtering rules here.
Code:
# iptables -nvL
Put the rules in code tags so that they're readable.
 
Old 03-06-2007, 02:11 PM   #3
cheesus
Member
 
Registered: Jan 2005
Location: Munich, Germany
Distribution: SuSE
Posts: 186

Original Poster
Rep: Reputation: 25
Arrow It's the DSL router...

Thank you for your response.

I didn't realize my DSL router had the firewall activated, so
it has nothing to do with the Linux...

Still, I think it is strange behavior for a firewall to accept the
connection, then drop it, instead of just blocking the port...

Cheers, Tom.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
strange behaviour marsques Slackware 11 02-15-2006 06:05 PM
Strange Behaviour! joshuarowley LQ Suggestions & Feedback 1 12-08-2005 03:36 PM
Strange behaviour Anmol SUSE / openSUSE 2 10-27-2005 11:05 PM
ssh connection drops jeffpoulsen Linux - Networking 5 10-08-2003 09:57 PM
Strange Behaviour mikeyt_3333 Linux - General 4 08-06-2001 03:07 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 01:55 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration