Linux Netfilter discussions
 help / color / mirror / Atom feed
* How to check why HTTP proxy is not accessible from outside?
@ 2018-02-10  5:28 Peng Yu
  2018-02-11 21:03 ` SV: " André Paulsberg-Csibi (IBM Consultant)
  0 siblings, 1 reply; 3+ messages in thread
From: Peng Yu @ 2018-02-10  5:28 UTC (permalink / raw)
  To: netfilter

Hi,

I have squid HTTP proxy running on both of the following servers
(server 1 and 2). But the proxy service on server1 can not be accessed
from outside.

I am not familiar with the output of iptables. Could the difference
explain why proxy on server1 is not accessible? Thanks.

server1:~$ sudo iptables -L
Chain INPUT (policy ACCEPT)
target     prot opt source               destination
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:smtp reject-with icmp-port-unreachable
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:http reject-with icmp-port-unreachable
ACCEPT     tcp  --  localhost            anywhere             tcp dpt:5900
ACCEPT     tcp  --  localhost            anywhere             tcp dpt:5901
ACCEPT     tcp  --  localhost            anywhere             tcp dpt:5902
ACCEPT     tcp  --  localhost            anywhere             tcp dpt:5903
ACCEPT     tcp  --  localhost            anywhere             tcp dpt:5904
ACCEPT     tcp  --  localhost            anywhere             tcp dpt:5905
ACCEPT     tcp  --  localhost            anywhere             tcp dpt:5906
ACCEPT     tcp  --  localhost            anywhere             tcp dpt:5907
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:5900 reject-with icmp-port-unreachable
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:5901 reject-with icmp-port-unreachable
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:5902 reject-with icmp-port-unreachable
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:5903 reject-with icmp-port-unreachable
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:5904 reject-with icmp-port-unreachable
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:5905 reject-with icmp-port-unreachable
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:5906 reject-with icmp-port-unreachable
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:5907 reject-with icmp-port-unreachable
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:imap2 reject-with icmp-port-unreachable
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:imaps reject-with icmp-port-unreachable

Chain FORWARD (policy ACCEPT)
target     prot opt source               destination

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination
server2:~$  sudo iptables -L
Chain INPUT (policy ACCEPT)
target     prot opt source               destination
ACCEPT     tcp  --  localhost            anywhere             tcp dpt:5900
ACCEPT     tcp  --  localhost            anywhere             tcp dpt:5901
ACCEPT     tcp  --  localhost            anywhere             tcp dpt:5902
ACCEPT     tcp  --  localhost            anywhere             tcp dpt:5903
ACCEPT     tcp  --  localhost            anywhere             tcp dpt:5904
ACCEPT     tcp  --  localhost            anywhere             tcp dpt:5905
ACCEPT     tcp  --  localhost            anywhere             tcp dpt:5906
ACCEPT     tcp  --  localhost            anywhere             tcp dpt:5907
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:5900 reject-with icmp-port-unreachable
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:5901 reject-with icmp-port-unreachable
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:5902 reject-with icmp-port-unreachable
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:5903 reject-with icmp-port-unreachable
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:5904 reject-with icmp-port-unreachable
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:5905 reject-with icmp-port-unreachable
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:5906 reject-with icmp-port-unreachable
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:5907 reject-with icmp-port-unreachable
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:smtp reject-with icmp-port-unreachable
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:http reject-with icmp-port-unreachable
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:imap2 reject-with icmp-port-unreachable
REJECT     tcp  --  anywhere             anywhere             tcp
dpt:imaps reject-with icmp-port-unreachable

Chain FORWARD (policy ACCEPT)
target     prot opt source               destination

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination

-- 
Regards,
Peng

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2018-02-11 22:20 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2018-02-10  5:28 How to check why HTTP proxy is not accessible from outside? Peng Yu
2018-02-11 21:03 ` SV: " André Paulsberg-Csibi (IBM Consultant)
2018-02-11 22:20   ` Neal P. Murphy

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox