LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-24-2003, 12:20 PM   #1
Tigger
Member
 
Registered: May 2003
Posts: 168

Rep: Reputation: 30
iptables help


Hi i am new to linux and am having trouble setting up my iptables.

I want to host my own web server and mail server.

I would like to know what changes need to be made to iptables to allow
web and mail to come through. The reason why i think it is my
firewall is because i can send mail out but i cannot receive mail. I
can view the web and i can view my web page locally but i cannot
access it from the internet.

I get an unknown host error when i try to reply to a mail message. I can also view my web page from the server but not from another machine on the lan. When i try from another machine on the lan it comes up with the username and password for the adsl modem/router. From the internet, the error i receive is "this page cannot be displayed".

This is what i have added to iptables by typing from a terminal
sesssion

iptables -A INPUT -p tcp --dport 80 -j ACCEPT
iptables -A INPUT -p tcp --dport 25 -j ACCEPT

Do i need to add anything else?

I have an adsl router which has an internal ip address and an external
ip address allocated to it by the isp. Then my server runs off the
switch and is not directly attached to the router.

Do i need to add the following lines?

"iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j DNAT --to
internal ip address" and do the same for port 25?

How do i get the external ip address to be forwarded to the router and
then to the internal ip address of my machine?

I have a dynalink adsl router, one port. i have added the following
nat commands to open up ports 80 and 25. "inbound add 80/tcp internal
ip address - add a rule" and "inbound add 25/tcp internal ip address -
add a rule"

Any ideas anyone?
 
Old 09-24-2003, 03:53 PM   #2
zatriz
Member
 
Registered: Aug 2003
Location: Seattle, Wa
Distribution: Fedora,Trustix,Debian
Posts: 290

Rep: Reputation: 30
from looking at the problem to me it looks more like a routing problem with the adsl modem than the mail and web servers.i would first check if you can ping and trace route to the server and then work on the web and mail server
 
Old 09-24-2003, 04:25 PM   #3
fragglehorn
Member
 
Registered: Oct 2002
Location: I-Town, NY
Distribution: Debian, Slackware
Posts: 130

Rep: Reputation: 15
Might not be a routing problem at all. Do you have dns and pop (or imap) properly configured and running?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
An error occured getting IPtables status from the command /etc/rc.d/init.d/iptables s CrazyMAzeY Linux - Newbie 10 08-12-2010 05:25 AM
Iptables - Couldn't load target `ACCPET':/lib/iptables/libipt_ACCPET.so: z00t Linux - Security 3 01-26-2004 02:24 AM
IPtables Log Analyzer from http://www.gege.org/iptables/ brainlego Linux - Software 0 08-11-2003 06:08 AM
iptables book wich one can you pll recomment to be an iptables expert? linuxownt Linux - General 2 06-26-2003 04:38 PM
My iptables script is /etc/sysconfig/iptables. How do i make this baby execute on boo ForumKid Linux - General 3 01-22-2002 07:36 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 09:48 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration