* help me with firewall+drop by default
@ 2004-03-05 1:24 verito verito
2004-03-05 1:37 ` Antony Stone
0 siblings, 1 reply; 4+ messages in thread
From: verito verito @ 2004-03-05 1:24 UTC (permalink / raw)
To: netfilter
Firewall was denied , Just for default I'm sending, the (setting up) that
is able to access into the web , but I can't access into the mail server
(POP), and some web pages that requiered the Ports (443,21,23,25,110), I
hope. I will clear , if there is any question just replying me , Thanks
iptables -P INPUT DROP
iptables -P OUTPUT DROP
iptables -P FORWARD DROP
iptables -t nat -A PREROUTING -t tcp --dport 80 -j REDIRECT --to-port 8080
iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE
echo "1" > /proc/sys/net/ipv4/ip_forward
iptables -A INPUT -i eth0 -s 0/0 -d 0/0 -j ACCEPT
iptables -A -i lo -s 0/0 -d 0/0 -j ACCEPT
iptables -A FORWARD -i eth1 -o eth0 -m state --state ESTABLISHED,RELATED -j
ACCEPT
iptables -A INPUT -i eth1 -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A FORWARD -i eth0 -o eth1 -j ACCEPT
iptables -A OUTPUT -j ACCEPT
https,correo,msn
USING REDHAT 8
_________________________________________________________________
Charla con tus amigos en línea mediante MSN Messenger:
http://messenger.latam.msn.com/
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: help me with firewall+drop by default
2004-03-05 1:24 help me with firewall+drop by default verito verito
@ 2004-03-05 1:37 ` Antony Stone
0 siblings, 0 replies; 4+ messages in thread
From: Antony Stone @ 2004-03-05 1:37 UTC (permalink / raw)
To: netfilter
On Friday 05 March 2004 1:24 am, verito verito wrote:
> Firewall was denied , Just for default I'm sending, the (setting up)
> that is able to access into the web , but I can't access into the mail
> server (POP), and some web pages that requiered the Ports
> (443,21,23,25,110), I hope. I will clear , if there is any question just
> replying me , Thanks
Where are you tryuing to access the POP3 server from and to?
In other words, where is your client (compared to eth0 adn eth1 in your
rules), and is the server running on the machine with these rules, or on some
other server being routed through this one?
> iptables -P INPUT DROP
> iptables -P OUTPUT DROP
> iptables -P FORWARD DROP
> iptables -t nat -A PREROUTING -t tcp --dport 80 -j REDIRECT --to-port 8080
> iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE
> echo "1" > /proc/sys/net/ipv4/ip_forward
> iptables -A INPUT -i eth0 -s 0/0 -d 0/0 -j ACCEPT
> iptables -A -i lo -s 0/0 -d 0/0 -j ACCEPT
> iptables -A FORWARD -i eth1 -o eth0 -m state --state ESTABLISHED,RELATED -j
> ACCEPT
> iptables -A INPUT -i eth1 -m state --state ESTABLISHED,RELATED -j ACCEPT
> iptables -A FORWARD -i eth0 -o eth1 -j ACCEPT
> iptables -A OUTPUT -j ACCEPT
Antony.
--
90% of networking problems are routing problems.
9 of the remaining 10% are routing problems in the other direction.
The remaining 1% might be something else, but check the routing anyway.
Please reply to the list;
please don't CC me.
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: help me with firewall+drop by default
@ 2004-03-05 2:33 verito verito
0 siblings, 0 replies; 4+ messages in thread
From: verito verito @ 2004-03-05 2:33 UTC (permalink / raw)
To: netfilter
>From: Antony Stone <Antony@Soft-Solutions.co.uk>
>To: netfilter@lists.netfilter.org
>Subject: Re: help me with firewall+drop by default
>Date: Fri, 5 Mar 2004 01:37:26 +0000
>
>On Friday 05 March 2004 1:24 am, verito verito wrote:
>
> > Firewall was denied , Just for default I'm sending, the (setting up)
> > that is able to access into the web , but I can't access into the
>mail
> > server (POP), and some web pages that requiered the Ports
> > (443,21,23,25,110), I hope. I will clear , if there is any question just
> > replying me , Thanks
>
>Where are you tryuing to access the POP3 server from and to?
>
>In other words, where is your client (compared to eth0 adn eth1 in your
>rules), and is the server running on the machine with these rules, or on
>some
>other server being routed through this one?
****************************************************
eth0=lan
eth1=internet
The server pop3 is external I must open the ports 110 and 25
Since I use the outlook as client of mail in order that it could send and
receive post office
***********************************************************************
> > iptables -P INPUT DROP
> > iptables -P OUTPUT DROP
> > iptables -P FORWARD DROP
> > iptables -t nat -A PREROUTING -t tcp --dport 80 -j REDIRECT --to-port
>8080
> > iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE
> > echo "1" > /proc/sys/net/ipv4/ip_forward
> > iptables -A INPUT -i eth0 -s 0/0 -d 0/0 -j ACCEPT
> > iptables -A -i lo -s 0/0 -d 0/0 -j ACCEPT
> > iptables -A FORWARD -i eth1 -o eth0 -m state --state ESTABLISHED,RELATED
>-j
> > ACCEPT
> > iptables -A INPUT -i eth1 -m state --state ESTABLISHED,RELATED -j ACCEPT
> > iptables -A FORWARD -i eth0 -o eth1 -j ACCEPT
> > iptables -A OUTPUT -j ACCEPT
>
>Antony.
>
>--
>90% of networking problems are routing problems.
>9 of the remaining 10% are routing problems in the other direction.
>The remaining 1% might be something else, but check the routing anyway.
>
> Please reply to the
>list;
> please don't CC
>me.
>
>
_________________________________________________________________
MSN Amor: busca tu ½ naranja http://latam.msn.com/amor/
^ permalink raw reply [flat|nested] 4+ messages in thread
[parent not found: <BAY7-F103tpgWtfb8tW0003bc47@hotmail.com>]
* Re: help me with firewall+drop by default
[not found] <BAY7-F103tpgWtfb8tW0003bc47@hotmail.com>
@ 2004-03-05 2:43 ` Antony Stone
0 siblings, 0 replies; 4+ messages in thread
From: Antony Stone @ 2004-03-05 2:43 UTC (permalink / raw)
To: netfilter
On Friday 05 March 2004 2:28 am, verito verito wrote:
> From: Antony Stone <Antony@Soft-Solutions.co.uk>
>
> >Where are you trying to access the POP3 server from and to?
> >
> >In other words, where is your client (compared to eth0 and eth1 in your
> >rules), and is the server running on the machine with these rules, or on
> >some other server being routed through this one?
>
> eth0=lan
> eth1=internet
> The server pop3 is external I must open the ports 110 and 25
> Since I use the outlook as client of mail in order that it could send and
> receive post office
In that case the ruleset you have posted below should work, because requests
come from eth0, get routed to eth1, and you have a rule:
> iptables -A FORWARD -i eth0 -o eth1 -j ACCEPT
Replies come back on eth1 and get routed to eth0:
> iptables -A FORWARD -i eth1 -o eth0 -m state --state ESTABLISHED,RELATED
> -j ACCEPT
And you are SNATting packets on their way out to the Internet:
> iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE
So, why is this setup not working?
1. Is that your complete ruleset?
2. What does "iptables -L -nvx; iptables -L -t nat -nvx" show for the packet
counters on each rule?
3. Is your mail client correctly resolving the hostname of the server in order
to try connecting to it by POP3?
Do other protocols (except for HTTP/port 80, which you are redirecting) work?
For example, ftp? ssh? traceroute? ping? telnet!? whois?
Hope this helps point you in the right direction.
Regards,
Antony.
--
I'm pink, therefore I'm Spam.
Please reply to the list;
please don't CC me.
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2004-03-05 2:43 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-03-05 1:24 help me with firewall+drop by default verito verito
2004-03-05 1:37 ` Antony Stone
-- strict thread matches above, loose matches on Subject: below --
2004-03-05 2:33 verito verito
[not found] <BAY7-F103tpgWtfb8tW0003bc47@hotmail.com>
2004-03-05 2:43 ` Antony Stone
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox