LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-24-2003, 10:24 PM   #1
Corin
Member
 
Registered: Jul 2003
Location: Jette, Brussels Hoofstedelijk Gewest
Distribution: Debian sid, RedHat 9, Suse 8.2
Posts: 446

Rep: Reputation: 31
How to get traceroute to work behind a firewall?


I have a firewall set up on a Red Hat 9 machine using IPTABLES and all seems to be secure and working as it should and if I use traceroute it works as expected.

On a Debian sid machine connected on the LAN to the Red Hat machine with firewall, network applications (ping, slogin, sftp etc) to external sites are all working as expected with the exception of traceroute.

Instead of getting the names back of the hosts on each step of the route, all I get is

* * * * *

Can anybody advise me as to the necessary IPTABLE rules for getting traceroute to work behind the firewall?
 
Old 07-24-2003, 11:05 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Usual source ports are UDP range 32769:65535, and usual dest ports are UDP range 33434:33523. (edit: you need unblocked ICMP as well)

Alternatively you could try for instance tcptraceroute.

Last edited by unSpawn; 07-24-2003 at 11:12 PM.
 
Old 07-25-2003, 12:05 AM   #3
Corin
Member
 
Registered: Jul 2003
Location: Jette, Brussels Hoofstedelijk Gewest
Distribution: Debian sid, RedHat 9, Suse 8.2
Posts: 446

Original Poster
Rep: Reputation: 31
Thank you for your rapid response.

Presumably I am okay on those points, since traceroute works on the firewall machine but behind the firewall.

But you comment about ICMP has caused me to remember that I still had IPTABLES rules active on the internal machine (because it has an analog modem dialout connection), which it turns out are the cause of the problem.

But the odd thing which remains is that from the firewall machine I see

1 my.internet.ip my.isp 41.849 ms 19.570 ms 13.178 ms
2 at-0-1-0-41.adsl2.02bnc.skynet.be (194.78.255.249) 13.379 ms 13.938 ms 37.186 ms
3 ae1-0.intlbnc3.skynet.be (194.78.0.142) 104.867 ms 16.591 ms 13.395 ms
4 gigabitethernet8-0.hsa2.Brussels1.Level3.net (212.3.234.21) 12.760 ms 13.563 ms 12.438 ms

but on the other machine I still get one entry blanked out

1 firewall_machine (192.168.1.2) 1 ms 0 ms 0 ms
2 * * * <<<<<<<<<----- where my.ip my.isp details should be
3 at-0-1-0-41.adsl2.02bnc.skynet.be (194.78.255.249) 13 ms 16 ms 12 ms
4 ae1-0.intlbnc3.skynet.be (194.78.0.142) 13 ms 117 ms 25 ms

Can you explain that one?

But thanks once again for helping me to solve the main problem.

ICMPs were being blocked -- not as it turned out from the firewall machine but by the firewall rules on the machine itself.
 
Old 07-25-2003, 08:26 AM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
The "easiest" way to troubleshoot firewall rulesets IMHO is to insert LOG target rules before making any final "destructive" decisions (DROP|REJ) in a chain. This allows you to track what get's dropped or rejected instead of forwarded, squished, smashed, mangled or whatever cruelties one tends to inflict on them packets.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Hardware Firewall - Will this work? phillips321 Linux - Networking 1 02-24-2005 07:16 AM
Firewall (Giptables) Can't seem to work... ImAnEwBiE Linux - Software 0 09-08-2004 10:13 PM
nmap and traceroute donot work rsnfunky Linux - Security 3 11-17-2003 09:59 AM
Why wont this work? (Firewall) Patryn999 Linux - Security 2 09-14-2003 10:59 PM
Getting around a work firewall with ssh Erice60rng Linux - Security 4 01-21-2003 07:07 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:31 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration