LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 01-01-2005, 12:28 PM   #1
trekk
Member
 
Registered: Oct 2003
Location: Charlotte, NC
Distribution: Fedora Core 6
Posts: 66

Rep: Reputation: 15
Webmin firewall using ip chains - samba/ip mask


Ok, so here's the issue - Trying to get samba working on the server again after the reinstall ... Everything up and running fine except I can't get samba working... of course it takes me screwing around with it off and on for days to figure out it's a firewall issue... heh.... So, I trying to use only webmin utilities or command line stuff for everything this time around (used firestarter last time - very easy setup) but the point is to learn right? So I got all my ports for p2p and stuff and set up the following in webmin -

Accept If protocol is TCP and source port is 137:139
Accept If protocol is UDP and source port is 137:139
Accept If protocol is UDP and source port is 445

===

Still doesn't work - felt like I missed something - -- like a port that needed to be opened... so I shut off the firewall and samba works fine of course so it still has to be the firewall -

===

So I decided to setup an allow on the entire ip - like :

Accept If source is 192.168.0.101 - currently my notebook - ...

works fine after that... so I was going to try to setup a mask like:

192.168.0.* so that all ip's on the network had no problems - but of course it won't let you do it....

I've tried to use 192.168.0.0/255 ... and different variables for masking but they either error out or don't allow the connection....

so my question is how to I ?

Also - someone want to give me some tips on firewalls - this is my configuration so far: the top 7 lines we're there when I started .. don't have a clue what the 224.0.0.251 is.. but just left it.... ---- any help would be appreciated -

====

Accept If input interface is lo
Accept If protocol is ICMP and ICMP type is any
Accept If protocol is 50
Accept If protocol is 51
Accept If protocol is UDP and destination is 224.0.0.251 and destination port is 5353
Accept If protocol is UDP and destination port is 631
Accept If state of connection is ESTABLISHED,RELATED
Accept If protocol is TCP and destination port is 22 and state of connection is NEW
Accept If protocol is TCP and destination port is 80 and state of connection is NEW
Accept If protocol is TCP and destination port is 21 and state of connection is NEW
Accept If protocol is TCP and destination port is 8291 and state of connection is NEW
Accept If protocol is TCP and source port is 1214
Accept If protocol is TCP and source port is 6346
Accept If protocol is TCP and source port is 5000
Accept If protocol is TCP and source port is 5555
Accept If protocol is TCP and source port is 7777
Accept If protocol is TCP and source port is 8311
Accept If protocol is TCP and source port is 8875
Accept If protocol is TCP and source port is 6257
Accept If protocol is UDP and source port is 6699
Accept If protocol is TCP and source port is 6346
Accept If protocol is TCP and source port is 1215
Accept If protocol is TCP and source port is 16211
Accept If protocol is TCP and source port is 3905
Accept If protocol is TCP and source port is 1718
Accept If protocol is TCP and source port is 1217
Accept If protocol is TCP and source port is 1213
Accept If protocol is TCP and source port is 137:139
Accept If protocol is UDP and source port is 137:139
Accept If protocol is UDP and source port is 445
Accept If source is 192.168.0
Reject Always

====


thanx!
 
Old 11-11-2005, 11:58 PM   #2
scotter
LQ Newbie
 
Registered: Jan 2005
Location: Midlands, UK
Posts: 6

Rep: Reputation: 0
I'm sure you've figured it out by now but for the reference of other ppl who hit this question, the source
adresses should be typed in in the following format

192.168.0.0/24 (IPs 192.168.0.1 -> 192.168.0.254) (Class C Network)
or
192.168.1.0/24 (IPs 192.168.1.1 -> 192.168.1.254) (Class C Network)
or
172.16.0.0/16 (IPs 172.16.0.1 -> 172.16.254.254) (Class B Network)
or
10.0.0.0/8 (IPs 10.0.0.1 -> 10.254.254.254) (Class A Network)
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
college firewall problem and webmin berrance Linux - Software 4 04-27-2005 07:50 AM
samba create mask msound Linux - Networking 1 03-23-2005 08:20 PM
Samba - Create Mask/Mode anilnatha Linux - Software 8 07-26-2004 06:27 PM
firewall blocking teamspeak webmin??? GrumpyGnome Linux - Software 1 06-12-2004 07:18 PM
FTP protocol and Webmin/squid/firewall--help ! dasilva Linux - Networking 1 10-10-2003 07:52 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 05:15 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration