Iptables isn't allowing any outgoing connections
I have a vps which is on an openvz system and it's running centos 5.3 fully patched. Iptables is setup for used in the VEs and I'm not exceeding numiptent. I'm using the iptables rules found at http://www.groovygrails.de/blog/groo...our_vps_with_a
which seems to be exactly what I want. When I have it loaded websites, email, ftp, ssh everything works. From my understanding of the script it should allow all outgoing connections. The problem comes when I ssh in I can't get any outgoing connections, no dns lookups, no ftp, no http, yum doesn't work (can't resolve), no pings no traceroutes, nothing. If I disable iptables I have outgoing connections so I think that's where the problem lays. This is the ouput from iptables -L with it loaded: Code:
Chain INPUT (policy DROP) Thanks |
I've done some more troubleshooting and using tcpdump I can see the outgoing dig (for example) requests and I see the incoming packets from the dns server in tcpdump while dig reports a time out. So it looks like my problem is with the input filters. Time to start troubleshooting them.
edit: looks like my -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT isn't seeing the related connections at all, where do I go from here? |
All times are GMT -5. The time now is 04:36 AM. |