LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Mandriva
User Name
Password
Mandriva This Forum is for the discussion of Mandriva (Mandrake) Linux.

Notices


Reply
  Search this Thread
Old 07-07-2010, 04:22 AM   #1
mongo86
LQ Newbie
 
Registered: Jul 2010
Posts: 2

Rep: Reputation: 0
Mandrake security MNF2 - shorewall "REJECT"


Hello! Hopefully someone more knowledgable than me can assist.

I have an old dedicated firewall that I chose to install mandrake security MNF2 on. The installation went fine, at the end of which I was reminded that all future configuration should be done through the web UI.

The problem is that when I attempt to connect to the UI from another machine, I can see the connection requests being rejected by shorewall. I read on another post http://www.linuxquestions.org/questi...-error-271618/ that the web interface is not set up by default, although it is the only real way to configure it. Unfortunately, the thread poster doesnt seem to have explained quite how he fixed the issue.

Im fairly comfortable with command-line OSs and understand basic Linux commands, etc, but I have no idea how to stop shorewall blocking my connections.

I read a little about the so-called "fool's firewall", but this issue doesnt seem to be affecting me (im connecting only the LAN port on my firewall directly to another machine)

Any help would be greatly appreciated.

Many thanks,

Ollie
 
Old 07-07-2010, 11:23 PM   #2
paulsm4
LQ Guru
 
Registered: Mar 2004
Distribution: SusE 8.2
Posts: 5,863
Blog Entries: 1

Rep: Reputation: Disabled
The poster in the link you referred to was installing MNF2 on a PC, using an .iso file (presumably, copied to a bootable CD). He was able to fix it by booting from his install media.

If you can boot your "dedicated firewall" from a CD/DVD, I'd suggest doing so.

Otherwise, if it's an embedded device (like a router), you should be able to hit the hardware "reset" button.

If all else fails, it might make a good doorstop or paperweight

'Hope that helps .. PSM
 
Old 07-17-2010, 08:29 AM   #3
mongo86
LQ Newbie
 
Registered: Jul 2010
Posts: 2

Original Poster
Rep: Reputation: 0
thanks for your reply Paul. I have ended up using Vyatta instead. It has much more comprehensive documentation, so I'm up and running with it
 
Old 07-17-2010, 12:01 PM   #4
rjcooks
Member
 
Registered: Jan 2008
Location: NE AR USA
Distribution: Manjaro Linux; Previously RPM based: openSUSE ...Mandriva-2010.1.
Posts: 85

Rep: Reputation: 22
Quote:
Originally Posted by mongo86 View Post
[snip]
The problem is that when I attempt to connect to the UI from another machine, I can see the connection requests being rejected by shorewall. [snip]
Im fairly comfortable with command-line OSs and understand basic Linux commands, etc, but I have no idea how to stop shorewall blocking my connections.
[snip]
For reference, Shorewall, like (almost) all Linux OS based firewalls, use iptables v4 &|R v6. To open or close connections, one adjusts the iptables "rules" which can be done from (most) firewall interfaces, or, if fairly adept with iptables rules, edit the file and appropriate lines of code directly.
It may sound hard but once the language of iptables is learned, it is not. It is dangerous because the wrong code can block or open everything( not sure which is worse ... ) so one needs to be careful.
The point being that whether one is using a local firewall like Shorewall or an external dedicated firewall(or both as in OP's case), an understanding iptables is essential to managing the application. Expert knowledge is not needed for management but the basics are.

FWIW, I have not had to edit the iptables directly for years. The Smoothwall interface(web & openssh) is clumsy but sufficient to get the tasks done. I do not use Shorewall as having two firewalls running was redundant and, as it appeared, a total waste of time( I'm not that paranoid. ). Not having the iptables and Shorewall overhead on the local system(s) makes the system easier to use for many things. I basically replaced Shorewall with clamav... and, dependent upon general security problems|alerts, IDS(snort, which, BTW, can run on the dedicated Smoothwall firewall).

Last edited by rjcooks; 07-17-2010 at 12:03 PM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Postfix "Content Filter" setup to reject emails with too many recipients in TO: field bahadirtonguc Linux - Server 10 05-27-2010 02:07 AM
Postfix: how to reject incoming mail as in Sendmail's "error:nouser"? Zippy1970 Linux - Server 24 10-01-2008 08:20 AM
Why does "su" reject my password if I can log in as root? wtf? neeyo Linux - General 10 12-21-2006 07:46 PM
Mandrake 10: Issues with "higher" security setting and web server maverick106 Mandriva 6 04-26-2004 10:39 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Mandriva

All times are GMT -5. The time now is 02:15 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration