Cheers,
Mark
1. iptables woes - may be RELATED related :)
Hi - I've just started using iptables and I'm having trouble. I
basically want my firewall setup to bar all connections except the ones
coming from my uni, and I had it doing this just fine in ipchains. Now I
have a wierd problem, where if I telnet into uni and then back out to my
machine, iptables lets the connection thru just fine, but if I'm at uni
and I try to telnet in I get no response. Here's my
/etc/sysconfig/iptables:
# Generated by iptables-save v1.2.2 on Fri Aug 31 12:54:36 2001
*nat
:PREROUTING ACCEPT [17:708]
:POSTROUTING ACCEPT [35:2109]
:OUTPUT ACCEPT [35:2109]
COMMIT
# Completed on Fri Aug 31 12:54:36 2001
# Generated by iptables-save v1.2.2 on Fri Aug 31 12:54:36 2001
*mangle
:PREROUTING ACCEPT [670:68228]
:OUTPUT ACCEPT [738:50393]
COMMIT
# Completed on Fri Aug 31 12:54:36 2001
# Generated by iptables-save v1.2.2 on Fri Aug 31 12:54:36 2001
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [738:50393]
:GLEN - [0:0]
-A INPUT -j GLEN
-A FORWARD -j GLEN
-A GLEN -i eth0 -p udp -m udp --sport 67:68 --dport 67:68 -j ACCEPT
-A GLEN -s 203.164.20.10 -p udp -m udp --dport 53 -j ACCEPT
-A GLEN -s 203.164.20.11 -p udp -m udp --dport 53 -j ACCEPT
-A GLEN -m state --state RELATED,ESTABLISHED -j ACCEPT
-A GLEN -i lo -j ACCEPT
-A GLEN -s 129.94.242.0/255.255.255.0 -j ACCEPT
-A GLEN -j DROP
COMMIT
# Completed on Fri Aug 31 12:54:36 2001
The line which is supposed to allow incoming connections from uni is the
second last one in the GLEN chain.
Can anyone help me troubleshoot this? Any help would be really
appreciated. Also, if you spot any glaring security holes, please let me
know, as I'm really new to firewalling and basically have nfi beyond what
I've tried to glean from a few HOWTO's.
Cheers,
Glen
2. fr problem using glade autoheader 'lklkl' not covered
7. ac13 and lp related problem
9. PROBLEM: 2.4.21 ICH5 SATA related hang during boot
10. Problem related to Xfree86-3.3.2
11. Wierd DOS boot problem --DOSEMU related???
12. NFS related network problem
13. booting problem related to linux network demon