All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Dermot Paikkos" <dermot@sciencephoto.com>
To: linux-admin@vger.kernel.org
Subject: Re: samba: unreachable - admin prohibited
Date: Fri, 29 Jul 2005 19:33:04 +0100	[thread overview]
Message-ID: <42EA8470.10323.75475D@localhost> (raw)
In-Reply-To: <4848.192.168.99.70.1122661523.squirrel@192.168.99.70>

On 29 Jul 2005 at 11:25, Scott Taylor wrote:

> 
> Dermot Paikkos said:
> > Hi
> >
> > The one area I am not sure about is the firewall. I left this
> > enabled during the install of redhat. The iptables are listed at the
> > end of this mail. portscan shows 139 running with netbios-ssn so I
> > am not sure if this means traffic is allowed through or not.
> >
> > Does anyone have any ideas?
> 
> I don't see any SMB or NMB allowed in your IPTABLES rulez.
> 
I guess the next question is how do I add a rule for smb and nmb or 
can I just turn it off to confirm that this is the source of the 
problem?

> > ============== iptables ================
> > Chain FORWARD (policy ACCEPT)
> > target     prot opt source               destination
> > RH-Firewall-1-INPUT  all  --  anywhere             anywhere
> >
> > Chain INPUT (policy ACCEPT)
> > target     prot opt source               destination
> > RH-Firewall-1-INPUT  all  --  anywhere             anywhere
> >
> > Chain OUTPUT (policy ACCEPT)
> > target     prot opt source               destination
> >
> > Chain RH-Firewall-1-INPUT (2 references)
> > target     prot opt source               destination
> > ACCEPT     all  --  anywhere             anywhere
> > ACCEPT     icmp --  anywhere             anywhere            icmp
> > any ACCEPT     ipv6-crypt--  anywhere             anywhere ACCEPT   
> >  ipv6-auth--  anywhere             anywhere ACCEPT     udp  -- 
> > anywhere             224.0.0.251         udp dpt:5353 ACCEPT     udp
> >  --  anywhere             anywhere            udp dpt:ipp ACCEPT    
> > all  --  anywhere             anywhere            state
> > RELATED,ESTABLISHED ACCEPT     tcp  --  anywhere            
> > anywhere            state NEW tcp dpt:ssh ACCEPT     tcp  -- 
> > anywhere             anywhere            state NEW tcp dpt:http
> > ACCEPT     tcp  --  anywhere             anywhere            state
> > NEW tcp dpt:ftp ACCEPT     tcp  --  anywhere             anywhere   
> >         state NEW tcp dpt:smtp REJECT     all  --  anywhere         
> >    anywhere            reject- with icmp-host-prohibited
> >
> 
> --
> Scott
> 


~~
Dermot Paikkos * dermot@sciencephoto.com
Network Administrator @ Science Photo Library
Phone: 0207 432 1100 * Fax: 0207 286 8668


  parent reply	other threads:[~2005-07-29 18:33 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-07-29 18:10 samba: unreachable - admin prohibited Dermot Paikkos
2005-07-29 18:28 ` Jens Knoell
     [not found] ` <4848.192.168.99.70.1122661523.squirrel@192.168.99.70>
2005-07-29 18:33   ` Dermot Paikkos [this message]
2005-07-29 18:55     ` Jens Knoell
2005-07-29 19:27       ` Dermot Paikkos
     [not found]     ` <42EA9A54.3516.CAC929@localhost>
2005-07-29 20:14       ` Scott Taylor
  -- strict thread matches above, loose matches on Subject: below --
2005-07-29 20:04 Scott Taylor

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=42EA8470.10323.75475D@localhost \
    --to=dermot@sciencephoto.com \
    --cc=linux-admin@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.