All of lore.kernel.org
 help / color / mirror / Atom feed
From: Sascha Reissner <sascha.reissner@toxicnet.de>
To: Jacob Friis Larsen <jfl@list.idg.dk>
Cc: netfilter@lists.netfilter.org
Subject: Re: Port is open but I am unable to connect
Date: Tue, 07 Sep 2004 21:35:04 +0200	[thread overview]
Message-ID: <413E0D68.6020208@toxicnet.de> (raw)
In-Reply-To: <413E0B9E.8010708@list.idg.dk>


just to make sure.. you are certain, that you want -s 1.2.3.4?

this means source ip is 1.2.3.4 (so the ip you connect from, not the ip 
you connect _to_)


Jacob Friis Larsen wrote:
> When I add -s 1.2.3.4 I am unable to connect to my server.
> nmap shows that the correct ports are open.
> Any ideas?
> 
> iptables -A INPUT -s 1.2.3.4 -j ACCEPT -p tcp --dport 22 -m state 
> --state NEW
> 
> This is my script:
> <script>
> #!/bin/sh
> 
> # Modules
> modprobe ip_conntrack_ftp
> 
> # Defaults
> iptables -P INPUT DROP
> iptables -P FORWARD DROP
> iptables -P OUTPUT DROP
> 
> # Flush
> iptables -t nat -F POSTROUTING
> iptables -t nat -F PREROUTING
> iptables -t nat -F OUTPUT
> iptables -F
> 
> # STATE RELATED for router
> iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
> 
> # Localhost
> iptables -A INPUT -i lo -j ACCEPT
> iptables -A OUTPUT -o lo -j ACCEPT
> 
> # Open ports on router for server/services
> iptables -A INPUT -s 1.2.3.4 -j ACCEPT -p tcp --dport 20 -m state 
> --state NEW
> iptables -A INPUT -s 1.2.3.4 -j ACCEPT -p tcp --dport 21 -m state 
> --state NEW
> iptables -A INPUT -s 1.2.3.4 -j ACCEPT -p tcp --dport 22 -m state 
> --state NEW
> iptables -A INPUT -j ACCEPT -p tcp --dport 25 -m state --state NEW
> iptables -A INPUT -j ACCEPT -p tcp --dport 80 -m state --state NEW
> iptables -A INPUT -j ACCEPT -p tcp --dport 143 -m state --state NEW
> iptables -A INPUT -j ACCEPT -p tcp --dport 993 -m state --state NEW
> </script>
> 
> Thanks,
> Jacob
> 
> 



  reply	other threads:[~2004-09-07 19:35 UTC|newest]

Thread overview: 10+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2004-09-07 19:27 Port is open but I am unable to connect Jacob Friis Larsen
2004-09-07 19:35 ` Sascha Reissner [this message]
2004-09-08  6:34   ` Jacob Friis Larsen
2004-09-07 20:19 ` Jason Opperisano
2004-09-08  6:38   ` Jacob Friis Larsen
2004-09-08 11:35     ` Jason Opperisano
2004-09-07 20:59 ` Aleksandar Milivojevic
2004-09-08  6:47   ` Jacob Friis Larsen
2004-09-09 10:17     ` Jacob Friis Larsen
2004-09-09 12:20       ` Jason Opperisano

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=413E0D68.6020208@toxicnet.de \
    --to=sascha.reissner@toxicnet.de \
    --cc=jfl@list.idg.dk \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.