LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-04-2006, 01:10 PM   #1
bschiett
Member
 
Registered: Feb 2005
Posts: 32

Rep: Reputation: 15
newbie trying to configure iptables with webmin


hi all,

i'm trying to setup a firewall on my server using webmin. the machine is running:

- ssh / sftp
- imap
- samba
- http and https
- smtp (local delivery of mails, it's not being used on the network to deliver mail, client programs use my ISP's smtp) -> the machine runs courier-imap, postfix, fetchmail and procmail

here are the firewall rules in webmin:

Action Condition Move Add
Accept If input interface is not eth0
Accept If protocol is TCP and TCP flags ACK (of ACK) are set
Accept If state of connection is ESTABLISHED
Accept If state of connection is RELATED
Accept If protocol is ICMP and ICMP type is echo-reply
Accept If protocol is ICMP and ICMP type is destination-unreachable
Accept If protocol is ICMP and ICMP type is source-quench
Accept If protocol is ICMP and ICMP type is time-exceeded
Accept If protocol is ICMP and ICMP type is parameter-problem
Accept If protocol is TCP and destination port is ssh
Accept If protocol is TCP and destination port is auth
Accept If protocol is ICMP and ICMP type is echo-request
Accept If protocol is TCP and destination port is www
Accept If protocol is UDP and destination port is www
Accept If protocol is TCP and destination port is sftp
Accept If protocol is TCP and destination port is imap
Accept If protocol is UDP and destination port is imap
Accept If protocol is TCP and destination port is https
Accept If protocol is TCP and destination port is imaps
Accept If protocol is UDP and destination port is imaps
Accept If protocol is UDP and destination port is 10000
Accept If protocol is TCP and destination port is 10000

I'm getting this when i scan with NMAP :

(The 1656 ports scanned but not shown below are in state: closed)
PORT STATE SERVICE
22/tcp open ssh
25/tcp open smtp
80/tcp open http
110/tcp open pop3
111/tcp open rpcbind
139/tcp open netbios-ssn
143/tcp open imap
445/tcp open microsoft-ds
809/tcp open unknown
993/tcp open imaps
995/tcp open pop3s
10000/tcp open snet-sensor-mgmt

I don't understand why rpcbind, pop3 etc are open even though I didn't open these in webmin?
any other suggestions or pointers to a good and simple tutorial on setting up a firewall? I tried google but had real difficulty understanding most of the firewall stuff I found.

thanks,
Bert
 
Old 01-04-2006, 04:04 PM   #2
Mara
Moderator
 
Registered: Feb 2002
Location: Grenoble
Distribution: Debian
Posts: 9,696

Rep: Reputation: 232Reputation: 232Reputation: 232
Where do you scan from? If it's the same machine, the scan ges through lo, not eth0, so the rules do not apply.
 
Old 01-05-2006, 02:09 AM   #3
bschiett
Member
 
Registered: Feb 2005
Posts: 32

Original Poster
Rep: Reputation: 15
scan

a different machine on my LAN ... a second linux server

i'm running Arch Linux
 
Old 01-05-2006, 04:58 PM   #4
Mara
Moderator
 
Registered: Feb 2002
Location: Grenoble
Distribution: Debian
Posts: 9,696

Rep: Reputation: 232Reputation: 232Reputation: 232
Hmm...Have you set the default policy to 'drop'?
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
configure SENDMAIL with webmin juanb Linux - Software 1 09-10-2009 01:50 AM
Can't configure ProFTPD from webmin rebel761 Linux - Networking 5 10-02-2005 10:26 AM
how to configure postfix with webmin? eozdoganci Linux - Newbie 0 06-07-2004 04:58 AM
How to configure iptables for VMWare? Thoddy Linux - Networking 2 01-26-2004 04:24 PM
Newbie about webmin... budhusa Linux - Security 6 12-15-2003 04:36 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:17 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration