LinuxQuestions.org
Latest LQ Deal: Latest LQ Deals
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 12-04-2011, 10:34 AM   #46
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985

Stop listing commands you have executed, start actually showing us the current iptables ruleset in place.
 
Old 12-04-2011, 10:43 AM   #47
agriz
Member
 
Registered: Nov 2011
Posts: 197

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by acid_kewpie View Post
Stop listing commands you have executed, start actually showing us the current iptables ruleset in place.
Cool!

Here are the results of iptables -L

Quote:
Chain INPUT (policy DROP)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp dpt:xx state NEW,ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp dpt:http state NEW,ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp dpt:https state NEW,ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp dpt:ftp state NEW,ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp spt:xx state ESTABLISHED

Chain FORWARD (policy DROP)
target prot opt source destination

Chain OUTPUT (policy DROP)
target prot opt source destination
ACCEPT tcp -- anywhere anywhere tcp spt:xx state ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp spt:http state ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp spt:https state ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp spt:ftp state ESTABLISHED
ACCEPT tcp -- anywhere anywhere tcp dpt:xx state NEW,ESTABLISHED
XX is the new port number of sshd.
If it is not secured rules, kindly post the rules which i should use on the server which is just used for website

Thanks
 
Old 12-04-2011, 12:33 PM   #48
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
OK, so yet again, I'll say you need default rules alreadyon this thread to allow standard outbound connections etc. and please use "iptables -vnL"

and I can promise you no one here cares in the slightest what your SSH port is. I will say though that as you've got "xx" as the source AND destination port in both directions, it does suggest you don't really understand what's going on as much as you really should.

Last edited by acid_kewpie; 12-04-2011 at 12:36 PM.
 
Old 12-04-2011, 01:35 PM   #49
agriz
Member
 
Registered: Nov 2011
Posts: 197

Original Poster
Rep: Reputation: Disabled
Quote:
Originally Posted by acid_kewpie View Post
I will say though that as you've got "xx" as the source AND destination port in both directions, it does suggest you don't really understand what's going on as much as you really should.
I too suspect that. But i was afraid to add it in one direction.
I believe the input rule is important to make ssh to the server.

The outbound rule might be saying that i want to ssh to another server using that port which is not required.
But As you know, I am not an expert and I really don't want to get blocked from sshing again.
 
Old 12-04-2011, 07:53 PM   #50
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Best run '/sbin/iptables-save > /tmp/iptables.rules' as root and then attach the plain text file.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Loading website problem surfer41 Debian 3 12-02-2006 08:11 PM
Problem loading website LetMeTryToo Linux - Software 2 11-23-2006 03:31 AM
wierd loading of website titanium_geek LQ Suggestions & Feedback 3 06-02-2005 10:16 AM
Not sure where to post for help with website loading AndeAnderson Linux - Newbie 5 04-15-2005 07:07 AM
Images not loading in website robojerk Linux - Newbie 1 02-17-2005 09:44 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 09:28 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration