LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-15-2012, 11:40 AM   #1
Fred Lappert
LQ Newbie
 
Registered: Sep 2007
Posts: 2

Rep: Reputation: 0
Shorewall issues on Debian Squeeze


We recently moved to a new server running Debian Squeeze.

A few weeks after putting the server into production, I did a routine apt-get dist-upgrade. Usually there are no surprises.

But we noticed all of a sudden we could not access mail via pop3, and we could not log in to Webmin.

After a bit of research on system logs, I discovered the issue related to Shorewall. Up until that point, I had never even heard of Shorewall (obviously I'm not s security expert).

As a temporary fix I can issues a "shorewall clear" to gain access to mail, and later issue a "shorewall restart" to block it again.

But I have some questions:

- if this was installed or enabled by the dist-upgrade, then what did it replace? Is it really needed or necessary? (or better, what value does it have?)

- and where and how would I change the Shorewall configuration so it doesn't block mail or webmin? If Shorewall is worth using, then there has to be a way to allow access to mail and Webmin.

Thank you.
 
Old 02-15-2012, 12:06 PM   #2
AlucardZero
Senior Member
 
Registered: May 2006
Location: USA
Distribution: Debian
Posts: 4,824

Rep: Reputation: 615Reputation: 615Reputation: 615Reputation: 615Reputation: 615Reputation: 615
Including the relevant error messages in your request for help is a big part of getting helped.

Shorewall is a firewall. I can't imagine it is a dependency of anything, so you must have installed it at some point. Next time you should pay more attention to what dist-upgrade does. The choice of having a firewall or not is your decision as the admin.

Shorewall has wonderful documentation. Browse it at http://shorewall.net/ . The basic config files are in /etc/shorewall. You should read them/the docs to figure out what to edit. There are also example configs for various setups at - iirc - /usr/share/doc/shorewall/examples. Of course there is a way to allow the services you want.

Last edited by AlucardZero; 02-15-2012 at 12:08 PM.
 
Old 02-15-2012, 12:44 PM   #3
Fred Lappert
LQ Newbie
 
Registered: Sep 2007
Posts: 2

Original Poster
Rep: Reputation: 0
Thanks for the reply. We just installed the new machine in mid-January. I did not install Shorewall... didn't even know it existed. Maybe it was there to begin with. But something happened when I did the dist-upgrade on January 28th. That's when I couldn't access pop3 mail or Webmin.

From Syslog, trying to connect with webmin

Quote:
Jan 28 13:18:25 shaw kernel: [14750395.928866] Shorewall:net2fw:DROP:IN=eth0 OUT= MAC=00:30:48:62:88:6e:00:19:2f:e8:fa:00:08:00 SRC=nnn.nnn.nnn.nnn DST=zzz.zzz.zzz.zzz LEN=52 TOS=0x00 PREC=0x00 TTL=116 ID=24815 DF PROTO=TCP SPT=55224 DPT=10000 WINDOW=8192 RES=0x00 SYN URGP=0
Jan 28 13:18:28 shaw kernel: [14750398.680029] Shorewall:net2fw:DROP:IN=eth0 OUT= MAC=00:30:48:62:88:6e:00:19:2f:e8:fa:00:08:00 SRC=nnn.nnn.nnn.nnn DST=zzz.zzz.zzz.zzz LEN=52 TOS=0x00 PREC=0x00 TTL=116 ID=24817 DF PROTO=TCP SPT=55223 DPT=10000 WINDOW=8192 RES=0x00 SYN URGP=0
and trying to access pop3 mail:

Quote:
Jan 28 13:19:33 shaw kernel: [14750463.864621] Shorewall:net2fw:DROP:IN=eth0 OUT= MAC=00:30:48:62:88:6e:00:19:2f:e8:fa:00:08:00 SRC=nnn.nnn.nnn.nnn DST=zzz.zzz.zzz.zzz LEN=52 TOS=0x00 PREC=0x00 TTL=116 ID=24845 DF PROTO=TCP SPT=55225 DPT=110 WINDOW=8192 RES=0x00 SYN URGP=0
Jan 28 13:19:33 shaw kernel: [14750463.906600] Shorewall:net2fw:DROP:IN=eth0 OUT= MAC=00:30:48:62:88:6e:00:19:2f:e8:fa:00:08:00 SRC=nnn.nnn.nnn.nnn DST=zzz.zzz.zzz.zzz LEN=52 TOS=0x00 PREC=0x00 TTL=116 ID=24847 DF PROTO=TCP SPT=55226 DPT=110 WINDOW=8192 RES=0x00 SYN URGP=0

Last edited by Fred Lappert; 02-15-2012 at 12:46 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
WLAN issues in Debian Squeeze RTL8188CE tondalar Debian 4 02-29-2012 12:01 PM
Various segmentation faults Debian Squeeze Virtualbox running on Debian Squeeze host fordwrench Debian 1 07-21-2011 03:55 AM
LXer: How To Upgrade Debian Lenny (Debian 5.0) To Squeeze (Debian 6.0) On Xen VPS LXer Syndicated Linux News 0 03-09-2011 05:20 AM
Issues w/Grub2 while trying to install Debian "squeeze" rickolai Linux - Newbie 1 02-07-2011 03:00 PM
Shorewall Issues kylibar Linux - Newbie 0 08-12-2008 12:46 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:35 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration