All of lore.kernel.org
 help / color / mirror / Atom feed
* Tracking down the source of proxy problem
@ 2006-05-01  9:13 David Leangen
  2006-05-01 10:41 ` Rob Sterenborg
  0 siblings, 1 reply; 5+ messages in thread
From: David Leangen @ 2006-05-01  9:13 UTC (permalink / raw)
  To: netfilter


Hello!

I have a network with an iptables-based firewall/proxy. Behind the proxy is
a machine running Postgres. Recently, many changes were made to the
installation.

Connecting to the Postgres DB works from within the network, but not from
without. I've run out of ideas for tracking down the error...

Could anybody kindly pass on some wise advice?


firewall iptables (in port number edited):

  *nat
  :PREROUTING ACCEPT [0:0]
  :POSTROUTING ACCEPT [0:0]
  :OUTPUT ACCEPT [0:0]
  -A PREROUTING -p tcp --dport ##INPORT## -j DNAT --to 192.168.2.10:5432
  -A PREROUTING -p udp --dport ##INPORT## -j DNAT --to 192.168.2.10:5432
  -A POSTROUTING -o ppp0 -j MASQUERADE
  COMMIT


db machine iptables:

  *filter
  :INPUT DROP [1:242]
  :FORWARD DROP [0:0]
  :OUTPUT ACCEPT [0:0]
  :LOG_DROP - [0:0]
  :LOG_ACCEPT - [0:0]
  :icmp_packets - [0:0]
  -A INPUT -p tcp -s 192.168.0.0/16 -m tcp --dport 5432 -j ACCEPT
  -A INPUT -j DROP


Thank you!!



^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2006-05-01 12:52 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-05-01  9:13 Tracking down the source of proxy problem David Leangen
2006-05-01 10:41 ` Rob Sterenborg
2006-05-01 11:33   ` David Leangen
2006-05-01 12:21     ` Rob Sterenborg
2006-05-01 12:52       ` David Leangen

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.