LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 09-05-2002, 04:48 PM   #16
pk21
Member
 
Registered: Jun 2002
Location: Netherlands - Amsterdam
Distribution: RedHat 9
Posts: 549

Original Poster
Rep: Reputation: 30

I already tryed that but it didnt seem to work.

But thanks for replying!
 
Old 09-06-2002, 03:21 AM   #17
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
We will need to see what you have in your iptables rules, check for conflicts etc..
Do you feel like emailing it to me?

Regards,
Peter
 
Old 09-06-2002, 06:58 AM   #18
pk21
Member
 
Registered: Jun 2002
Location: Netherlands - Amsterdam
Distribution: RedHat 9
Posts: 549

Original Poster
Rep: Reputation: 30
Chain INPUT (policy DROP)
ACCEPT tcp -- anywhere anywhere state ESTABLISHED
ACCEPT tcp -- anywhere anywhere state RELATED
ACCEPT tcp -- anywhere anywhere tcp dpt:ftp state NEW

Chain OUTPUT (policy ACCEPT)
ACCEPT tcp -- anywhere anywhere state ESTABLISHED
ACCEPT tcp -- anywhere anywhere state RELATED
 
Old 09-06-2002, 08:16 AM   #19
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
Change the ftp to 'spt:ftp'
You must accept packets FROM an ftp server

Regards,
Peter
 
Old 09-06-2002, 08:38 AM   #20
pk21
Member
 
Registered: Jun 2002
Location: Netherlands - Amsterdam
Distribution: RedHat 9
Posts: 549

Original Poster
Rep: Reputation: 30
No, i am running a ftp server. On this ftp server i am making my firewall rules.

Here is my last line out of my log file:
Sep 6 17:36:46 nbs-125 kernel: IPTABLESIN=eth0 OUT= MAC=00:48:54:56:35:89:00:d0:b7:1c:a9:b8:08:00 SRC=192.168.0.55 DST=192.168.0.125 LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=15551 DF PROTO=TCP SPT=57671 DPT=35748 WINDOW=5840 RES=0x00 SYN URGP=0
 
Old 09-06-2002, 10:54 AM   #21
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
Try this next..

Remove the two OUTPUT rules, they do nothing in an ACCEPT policy chain.
Change the ESTABLISHED & RELATED rules to be all protocols, not just tcp.
The segment of log file says nothing usefull...

Regards,
Peter.

Last edited by peter_robb; 09-06-2002 at 10:55 AM.
 
Old 09-06-2002, 11:49 AM   #22
pk21
Member
 
Registered: Jun 2002
Location: Netherlands - Amsterdam
Distribution: RedHat 9
Posts: 549

Original Poster
Rep: Reputation: 30
In the log you can see that there is a syn packet which gets blocked. That sys packet is for as far as i know only send with new connections.

And i already tryed without the output rulez, but monday i will try the other protocols.

Thanks for all the help so far.
 
Old 09-06-2002, 12:36 PM   #23
peter_robb
Senior Member
 
Registered: Feb 2002
Location: Szczecin, Poland
Distribution: Gentoo, Debian
Posts: 2,458

Rep: Reputation: 48
Yeah, any NEW SYN packets will get blocked other than port 21 destnation packets
(at least ideally!!)

Regards,
Peter
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
An error occured getting IPtables status from the command /etc/rc.d/init.d/iptables s CrazyMAzeY Linux - Newbie 10 08-12-2010 05:25 AM
Iptables - Couldn't load target `ACCPET':/lib/iptables/libipt_ACCPET.so: z00t Linux - Security 3 01-26-2004 02:24 AM
IPtables Log Analyzer from http://www.gege.org/iptables/ brainlego Linux - Software 0 08-11-2003 06:08 AM
iptables book wich one can you pll recomment to be an iptables expert? linuxownt Linux - General 2 06-26-2003 04:38 PM
My iptables script is /etc/sysconfig/iptables. How do i make this baby execute on boo ForumKid Linux - General 3 01-22-2002 07:36 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:36 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration