shorewall/iptables stopping all network traffic
I'm having a little bit of trouble configuring shorewall/iptables (I assume they're one in the same(?)). I installed it yesterday, and since have been having trouble. The main things i do online is check web sites and IRC. This is where the fun starts. As you've probably guessed, when I have shorewall/iptables running I can't do anything online. Can't ping, traceroute, or open IRC servers/web sites. Funny thing is, if I stop shorewall and open a connection to an IRC server, then restart shorewall, IRC works fine but still cannot access the internet. I tried searching this site, a lot of problem with shorewall, but no solutions listed. So, I figured I'd try again :). A little help in configuring iptables is what I'm really asking as I don't know much about TCP/IP yet. It also might be helpful to know I connect thru dial-up and kppp and have never had a problem.
|
I only use iptables firewall from the command line so may not be a lot of help.
iptables -L displays the filter tables iptables -F flushes them If you see them listed, they are very easy to read. Writing them is another story. |
Well shorewall is a GUI frontend for iptables, although albeit, not a very good one. Not very descriptive at all.
Maybe this information will help though, this is my output from: Code:
[root@localhost /home/scuzzy]# iptables -L |
BUMP
|
I take it there's nothing wrong with that output?
C'mon guys/gals |
Moved: This thread is more suitable in <Insert Forum Name Here> and has been moved accordingly to help your thread/question get the exposure it deserves.
|
Strange,
The default is to drop everything, then there is the acception to accept everything then line 4 of the input tables turns around and rejects everything again. Right there on that line, you aren't accepting any packets from anywhere using any protocol. There shouldn't be a surprise that you can't get any internet traffic. The problem with tools like shorewall, etc is that they can certainly jumble up the logical flow. iptables is a huge flowchart. If you reject everything on line 4 you can't turn around and say "Oh yeah, let this in" |
All times are GMT -5. The time now is 05:21 AM. |