LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 10-13-2009, 06:46 AM   #1
jamarski
LQ Newbie
 
Registered: Oct 2009
Posts: 4

Rep: Reputation: 0
can't ssh from external IP 2 Ethernal cards


Hi,

I have got a server with two Ethernet Cards. Eth0 has external static IP and Eth1 has internal IP. When both of interfaces are up i can't ssh to ext_IP (only local) but when i down eth1 ssh works great. No firewall, no iptables. Help Please.
 
Old 10-13-2009, 08:43 AM   #2
r3sistance
Senior Member
 
Registered: Mar 2004
Location: UK
Distribution: CentOS 6/7
Posts: 1,375

Rep: Reputation: 217Reputation: 217Reputation: 217
Perhaps trying setting the listenaddress in /etc/ssh/sshd_config to the external ip so it only listens to the external ip address. Not sure why you are seeing this behaviour at all.
 
Old 10-13-2009, 09:43 AM   #3
tommylovell
Member
 
Registered: Nov 2005
Distribution: Fedora, Redhat
Posts: 372

Rep: Reputation: 101Reputation: 101
With both interfaces up, can you ping the external IP address from where the ssh is failing?

(maybe a routing issue that is not allowing packets to return...)
 
Old 10-14-2009, 02:05 AM   #4
jamarski
LQ Newbie
 
Registered: Oct 2009
Posts: 4

Original Poster
Rep: Reputation: 0
Yes, I can
 
Old 10-14-2009, 06:02 AM   #5
smus
Member
 
Registered: Nov 2005
Location: Turkey
Distribution: Suse
Posts: 104

Rep: Reputation: 16
May be due to the firewall, which distro are you using?
 
Old 10-15-2009, 02:27 AM   #6
jamarski
LQ Newbie
 
Registered: Oct 2009
Posts: 4

Original Poster
Rep: Reputation: 0
CentOS release 5.3 (Final). Do you the thing is because of Centos?
 
Old 10-15-2009, 02:34 AM   #7
r3sistance
Senior Member
 
Registered: Mar 2004
Location: UK
Distribution: CentOS 6/7
Posts: 1,375

Rep: Reputation: 217Reputation: 217Reputation: 217
It's unlikely to be related to CentOS as CentOS generally can handle that kind of thing fairly easily. Can you copy and paste (into code tags) the output of the following command.

iptables -nvL
 
Old 10-15-2009, 02:34 AM   #8
linuxlover.chaitanya
Senior Member
 
Registered: Apr 2008
Location: Nagpur, India
Distribution: Cent OS 5/6, Ubuntu Server 10.04
Posts: 4,629

Rep: Reputation: Disabled
I have a similar setup on CentOS (same version) and still no issues. I can ssh from outside on the internet as well as from the intranet.
 
Old 10-15-2009, 02:52 AM   #9
jamarski
LQ Newbie
 
Registered: Oct 2009
Posts: 4

Original Poster
Rep: Reputation: 0
That's all i have
Code:
Chain INPUT (policy ACCEPT 3 packets, 806 bytes)
 pkts bytes target     prot opt in     out     source               destination
 2257  282K ACCEPT     all  --  lo     *       0.0.0.0/0            0.0.0.0/0
    0     0 DROP       all  --  *      *       1.0.0.0/8            0.0.0.0/0
    0     0 DROP       all  --  *      *       2.0.0.0/8            0.0.0.0/0
    0     0 DROP       all  --  *      *       112.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       113.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       114.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       115.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       173.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       174.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       175.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       176.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       177.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       178.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       179.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       180.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       181.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       182.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       183.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       184.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       185.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       186.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       187.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       197.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       223.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       240.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       241.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       242.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       243.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       244.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       245.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       246.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       247.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       248.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       249.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       250.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       250.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       251.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       252.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       253.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       254.0.0.0/8          0.0.0.0/0
    0     0 DROP       all  --  *      *       255.0.0.0/8          0.0.0.0/0
  846  111K TMP_DROP   all  --  *      *       0.0.0.0/0            0.0.0.0/0
  846  111K TALLOW     all  --  *      *       0.0.0.0/0            0.0.0.0/0
  846  111K TDENY      all  --  *      *       0.0.0.0/0            0.0.0.0/0
  846  111K TGALLOW    all  --  *      *       0.0.0.0/0            0.0.0.0/0
  846  111K TGDENY     all  --  *      *       0.0.0.0/0            0.0.0.0/0
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpts:135:139
    3   687 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpts:135:139
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:111
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:111
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:513
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:513
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:520
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:520
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:445
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:445
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:1433
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:1433
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:1434
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:1434
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:1234
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:1234
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:1524
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:1524
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:3127
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:3127
  842  110K IN_SANITY  all  --  *      *       0.0.0.0/0            0.0.0.0/0
  842  110K FRAG_UDP   all  --  *      *       0.0.0.0/0            0.0.0.0/0
  842  110K PZERO      all  --  *      *       0.0.0.0/0            0.0.0.0/0
  842  110K P2P        all  --  *      *       0.0.0.0/0            0.0.0.0/0
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:69
  539 78819 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:80
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:5060
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:5065
  245 13572 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:5918
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:6600
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpts:10000:20000
    0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:69
   21 11840 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:5060
    0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpts:10000:20000
    0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 3 limit: avg 30/sec burst 5
    0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 5 limit: avg 30/sec burst 5
    0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 11 limit: avg 30/sec burst 5
    0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 0 limit: avg 30/sec burst 5
    0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 30 limit: avg 30/sec burst 5
    0     0 ACCEPT     icmp --  *      *       0.0.0.0/0            0.0.0.0/0           icmp type 8 limit: avg 30/sec burst 5
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp flags:!0x17/0x02 state NEW
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           state RELATED,ESTABLISHED
   31  4416 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           state RELATED,ESTABLISHED
    0     0 ACCEPT     udp  --  *      *       194.204.152.34       0.0.0.0/0           udp spt:53 dpts:1023:65535
    0     0 ACCEPT     tcp  --  *      *       194.204.152.34       0.0.0.0/0           tcp spt:53 dpts:1023:65535
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp spt:53 dpts:1023:65535
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spt:53 dpts:1023:65535
    0     0 ACCEPT     udp  --  *      *       194.204.159.1        0.0.0.0/0           udp spt:53 dpts:1023:65535
    0     0 ACCEPT     tcp  --  *      *       194.204.159.1        0.0.0.0/0           tcp spt:53 dpts:1023:65535
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp spt:53 dpts:1023:65535
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spt:53 dpts:1023:65535
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp spts:1023:65535 dpt:21 state RELATED,ESTABLISHED
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           multiport dports 21,20 state RELATED,ESTABLISHED
    0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           multiport dports 21,20 state RELATED,ESTABLISHED
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp spt:5918 dpts:513:65535 state RELATED,ESTABLISHED
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp spts:1024:65535 dpt:5918 flags:0x17/0x02 state RELATED,ESTABL
ISHED
    0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:5918 state ESTABLISHED
    0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           state NEW udp dpts:33434:33534
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0
    6  1731 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0
    0     0 DROP       all  --  *      *       0.0.0.0/0            0.0.0.0/0

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination

Chain OUTPUT (policy ACCEPT 4 packets, 1110 bytes)
 pkts bytes target     prot opt in     out     source               destination
 2257  282K ACCEPT     all  --  *      lo      0.0.0.0/0            0.0.0.0/0
   93  4464 TCPMSS     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp flags:0x06/0x02 TCPMSS clamp to PMTU
    0     0 DROP       all  --  *      *       0.0.0.0/0            1.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            2.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            5.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            23.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            27.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            31.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            36.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            37.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            39.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            42.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            46.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            94.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            95.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            100.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            101.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            102.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            103.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            104.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            105.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            106.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            107.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            108.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            109.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            110.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            111.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            112.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            113.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            114.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            115.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            173.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            174.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            175.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            176.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            177.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            178.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            179.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            180.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            181.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            182.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            183.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            184.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            185.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            186.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            187.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            197.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            223.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            240.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            241.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            242.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            243.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            244.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            245.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            246.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            247.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            248.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            249.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            250.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            251.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            252.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            253.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            254.0.0.0/8
    0     0 DROP       all  --  *      *       0.0.0.0/0            255.0.0.0/8
 1029  480K TMP_DROP   all  --  *      *       0.0.0.0/0            0.0.0.0/0
 1029  480K TALLOW     all  --  *      *       0.0.0.0/0            0.0.0.0/0
 1029  480K TDENY      all  --  *      *       0.0.0.0/0            0.0.0.0/0
 1029  480K TGALLOW    all  --  *      *       0.0.0.0/0            0.0.0.0/0
 1029  480K TGDENY     all  --  *      *       0.0.0.0/0            0.0.0.0/0
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpts:135:139
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpts:135:139
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:111
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:111
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:513
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:513
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:520
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:520
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:445
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:445
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:1433
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:1433
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:1434
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:1434
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:1234
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:1234
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:1524
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:1524
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:3127
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:3127
 1027  480K OUT_SANITY  all  --  *      *       0.0.0.0/0            0.0.0.0/0
 1027  480K FRAG_UDP   all  --  *      *       0.0.0.0/0            0.0.0.0/0
 1027  480K PZERO      all  --  *      *       0.0.0.0/0            0.0.0.0/0
 1027  480K P2P        all  --  *      *       0.0.0.0/0            0.0.0.0/0
  965  465K ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpts:1024:65535 state RELATED,ESTABLISHED
   14  7839 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpts:1024:65535 state RELATED,ESTABLISHED
   19  1258 ACCEPT     udp  --  *      *       0.0.0.0/0            194.204.152.34      udp spts:1023:65535 dpt:53
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            194.204.152.34      tcp spts:1023:65535 dpt:53
    0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            194.204.152.34      udp spts:1023:65535 dpt:53
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            194.204.152.34      tcp spts:1023:65535 dpt:53
    0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            194.204.159.1       udp spts:1023:65535 dpt:53
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            194.204.159.1       tcp spts:1023:65535 dpt:53
    0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            194.204.159.1       udp spts:1023:65535 dpt:53
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            194.204.159.1       tcp spts:1023:65535 dpt:53
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp spt:21 dpts:1023:65535 state RELATED,ESTABLISHED
    0     0 ACCEPT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           multiport dports 21,20 state RELATED,ESTABLISHED
    0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           multiport dports 21,20 state RELATED,ESTABLISHED
    0     0 ACCEPT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           state NEW udp dpts:33434:33534
   29  6007 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0

Chain FRAG_UDP (2 references)
 pkts bytes target     prot opt in     out     source               destination
    0     0 DROP       udp  -f  *      *       0.0.0.0/0            0.0.0.0/0

Chain IN_SANITY (1 references)
 pkts bytes target     prot opt in     out     source               destination
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp flags:0x3F/0x00
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp flags:0x03/0x03
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp flags:0x06/0x06
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp flags:0x05/0x05
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp flags:0x11/0x01
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp flags:0x30/0x20
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp flags:0x18/0x08
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp flags:0x3F/0x29
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp flags:0x3F/0x37
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp flags:0x3F/0x3F
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp flags:0x3F/0x01

Chain P2P (2 references)
 pkts bytes target     prot opt in     out     source               destination
    0     0 REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:1214 reject-with icmp-port-unreachable
    0     0 REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp spt:1214 dpts:1024:65534 reject-with icmp-port-unreachable
    0     0 REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spts:1024:65534 dpt:1214 reject-with icmp-port-unreachable
    0     0 REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spt:1214 dpts:1024:65534 reject-with icmp-port-unreachable
    0     0 REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:2323 reject-with icmp-port-unreachable
    0     0 REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp spt:2323 dpts:1024:65534 reject-with icmp-port-unreachable
    0     0 REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spts:1024:65534 dpt:2323 reject-with icmp-port-unreachable
    0     0 REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spt:2323 dpts:1024:65534 reject-with icmp-port-unreachable
    0     0 REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp spts:1024:65534 dpts:4660:4678 reject-with icmp-port-unreacha
ble
    0     0 REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp spts:4660:4678 dpts:1024:65534 reject-with icmp-port-unreacha
ble
    0     0 REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spts:1024:65534 dpts:4660:4678 reject-with icmp-port-unreacha
ble
    0     0 REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spts:4660:4678 dpts:1024:65534 reject-with icmp-port-unreacha
ble
    0     0 REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:6257 reject-with icmp-port-unreachable
    0     0 REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp spt:6257 dpts:1024:65534 reject-with icmp-port-unreachable
    0     0 REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spts:1024:65534 dpt:6257 reject-with icmp-port-unreachable
    0     0 REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spt:6257 dpts:1024:65534 reject-with icmp-port-unreachable
    0     0 REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:6699 reject-with icmp-port-unreachable
    0     0 REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp spt:6699 dpts:1024:65534 reject-with icmp-port-unreachable
    0     0 REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spts:1024:65534 dpt:6699 reject-with icmp-port-unreachable
    0     0 REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spt:6699 dpts:1024:65534 reject-with icmp-port-unreachable
    0     0 REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:6346 reject-with icmp-port-unreachable
    0     0 REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp spt:6346 dpts:1024:65534 reject-with icmp-port-unreachable
    0     0 REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spts:1024:65534 dpt:6346 reject-with icmp-port-unreachable
    0     0 REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spt:6346 dpts:1024:65534 reject-with icmp-port-unreachable
    0     0 REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:6347 reject-with icmp-port-unreachable
    0     0 REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp spt:6347 dpts:1024:65534 reject-with icmp-port-unreachable
    0     0 REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spts:1024:65534 dpt:6347 reject-with icmp-port-unreachable
    0     0 REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spt:6347 dpts:1024:65534 reject-with icmp-port-unreachable
    0     0 REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp spts:1024:65534 dpts:6881:6889 reject-with icmp-port-unreacha
ble
    0     0 REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp spts:6881:6889 dpts:1024:65534 reject-with icmp-port-unreacha
ble
    0     0 REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spts:1024:65534 dpts:6881:6889 reject-with icmp-port-unreacha
ble
    0     0 REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spts:6881:6889 dpts:1024:65534 reject-with icmp-port-unreacha
ble
    0     0 REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:6346 reject-with icmp-port-unreachable
    0     0 REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp spt:6346 dpts:1024:65534 reject-with icmp-port-unreachable
    0     0 REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spts:1024:65534 dpt:6346 reject-with icmp-port-unreachable
    0     0 REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spt:6346 dpts:1024:65534 reject-with icmp-port-unreachable
    0     0 REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:7778 reject-with icmp-port-unreachable
    0     0 REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp spt:7778 dpts:1024:65534 reject-with icmp-port-unreachable
    0     0 REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spts:1024:65534 dpt:7778 reject-with icmp-port-unreachable
    0     0 REJECT     udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spt:7778 dpts:1024:65534 reject-with icmp-port-unreachable

Chain PROHIBIT (0 references)
 pkts bytes target     prot opt in     out     source               destination
    0     0 REJECT     all  --  *      *       0.0.0.0/0            0.0.0.0/0           reject-with icmp-host-prohibited

Chain PZERO (2 references)
 pkts bytes target     prot opt in     out     source               destination
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp dpt:0
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp dpt:0
    0     0 DROP       tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           tcp spt:0
    0     0 DROP       udp  --  *      *       0.0.0.0/0            0.0.0.0/0           udp spt:0

Chain RESET (0 references)
 pkts bytes target     prot opt in     out     source               destination
    0     0 REJECT     tcp  --  *      *       0.0.0.0/0            0.0.0.0/0           reject-with tcp-reset

Chain TALLOW (2 references)
 pkts bytes target     prot opt in     out     source               destination

Chain TDENY (2 references)
 pkts bytes target     prot opt in     out     source               destination

Chain TGALLOW (2 references)
 pkts bytes target     prot opt in     out     source               destination

Chain TGDENY (2 references)
 pkts bytes target     prot opt in     out     source               destination

Chain TMP_DROP (2 references)
 
Old 10-15-2009, 02:59 AM   #10
linuxlover.chaitanya
Senior Member
 
Registered: Apr 2008
Location: Nagpur, India
Distribution: Cent OS 5/6, Ubuntu Server 10.04
Posts: 4,629

Rep: Reputation: Disabled
Isnt it a better policy to default it to DROP and accept only those you want? Though it doesnt it seem to deny the connections, you can explicitly mention the rules to accept the connections from where you want. Also you could check the tcpwrappers as well.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
serial cards/ports & external modems for Linux Howard V Linux - Hardware 2 02-28-2005 07:02 PM
drivers for firewire external audio cards xround Linux - Hardware 0 02-22-2005 07:57 AM
Which ethernal card doed support for linux? vanhelsing Linux - Hardware 2 07-05-2004 03:03 AM
SSH how to configure differently for different cards (ie root access) datus Linux - Security 3 03-28-2004 03:48 PM
PCMCIA WLAN cards with External Antenna Connectors giddyupman Linux - Hardware 0 12-01-2003 12:56 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 07:46 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration