Re: IPTables and stat

2003-09-25 Thread Frank Tanner III
x27;m not disputing this. My comment below > was to account for > the syntax error when using the rpm command. > > > > > > --- Keith Morse <[EMAIL PROTECTED]> wrote: > > > On Wed, 17 Sep 2003, David E. Williams wrote: > > > > > > &

Re: IPTables and stat

2003-09-24 Thread Keith Morse
IL PROTECTED]> wrote: > > On Wed, 17 Sep 2003, David E. Williams wrote: > > > > > Hi all, > > > > > > I'm running iptables-1.2.6a-2 and am trying to > > update the package to > > > iptables-1.2.8-8.80.2. Doing "rpm -Fvh > > ipt

Re: IPTables and stat

2003-09-24 Thread Frank Tanner III
According to an e-mail I read on this, stat is part of the coreutils package. --- Keith Morse <[EMAIL PROTECTED]> wrote: > On Wed, 17 Sep 2003, David E. Williams wrote: > > > Hi all, > > > > I'm running iptables-1.2.6a-2 and am trying to > update the packa

Re: IPTables and stat

2003-09-24 Thread Keith Morse
On Wed, 17 Sep 2003, David E. Williams wrote: > Hi all, > > I'm running iptables-1.2.6a-2 and am trying to update the package to > iptables-1.2.8-8.80.2. Doing "rpm -Fvh iptables*.rpm" I get a failed > dependency "stat is needed by iptables-1.2.8-8.80.2"

Re: IPTables and stat

2003-09-17 Thread David E. Williams
Craig, Thanks. You saved the day for me! On Wed, 2003-09-17 at 15:52, Craig White wrote: > On Wed, 2003-09-17 at 13:06, David E. Williams wrote: > > Hi all, > > > > I'm running iptables-1.2.6a-2 and am trying to update the package to > > iptables-1.2.8-8.80.2.

Re: IPTables and stat

2003-09-17 Thread Craig White
On Wed, 2003-09-17 at 13:06, David E. Williams wrote: > Hi all, > > I'm running iptables-1.2.6a-2 and am trying to update the package to > iptables-1.2.8-8.80.2. Doing "rpm -Fvh iptables*.rpm" I get a failed > dependency "stat is needed by iptables-1.2.8-8.80

IPTables and stat

2003-09-17 Thread David E. Williams
Hi all, I'm running iptables-1.2.6a-2 and am trying to update the package to iptables-1.2.8-8.80.2. Doing "rpm -Fvh iptables*.rpm" I get a failed dependency "stat is needed by iptables-1.2.8-8.80.2". So I tried to determine what package stat is in with "rpm -q -f

Re: iptables

2003-06-04 Thread John Mathey
www.netfilter.org works, I get about 20 messages a day from there ( in non-digest form of course) mailing list and lots of help hth john At 04:40 PM 6/3/2003 -0400, you wrote: Where is the best place for iptables help? Is there a mailing list? I've tried the one listed at netfilter.org

Re: iptables

2003-06-04 Thread Roger
Around Tue,Jun 03 2003, at 04:40, Allan M. Stewart, wrote: > > when I list the rules in effect: (partial display) > > #iptables -L Try iptables -L -v Should list interfaces. -- Roger Morris [EMAIL PROTECTED] -- Psyche-list mailing list [EMAIL PROTECTED] https://www.redhat

iptables

2003-06-04 Thread Allan M. Stewart
Where is the best place for iptables help? Is there a mailing list? I've tried the one listed at netfilter.org, but that seems to be Tango Uniform (dead). Setting default policy doesn't seem to work with "REJECT" or "DENY". "ACCEPT" or "DROP&qu

Re: ULOGD and iptables -j ULOG?

2003-03-28 Thread Mike Vanecek
> > mmm... How about using a unique log prefix and then filtering? > For example: > > # /sbin/iptables -A INPUT -j LOG --log-level DEBUG --log-prefix "vanecek: " > ... > # grep vanecek /var/log/packets I use the --log-prefix to track each class of packets I am

Re: ULOGD and iptables -j ULOG?

2003-03-28 Thread Miguel M
Mike Vanecek wrote: BTW, this works better if one uses the kern.=debug format. You are right Mike! kern.=debug is more efficient Of course, I hope that nothing else is generating kern.debug messages mmm... How about using a unique log prefix and then filtering? For example: # /sbin/iptables

Re: ULOGD and iptables -j ULOG?

2003-03-27 Thread Mike Vanecek
irewall. > Watch out for the size of /var/log/packets: > > # touch /var/log/packets > # echo "kern.debug/var/log/packets" >> /etc/syslog.conf BTW, this works better if one uses the kern.=debug format. > # /sbin/iptables -A INPUT -j LOG --log-level DEBUG > # /

Re: ULOGD and iptables -j ULOG?

2003-03-26 Thread Mike Vanecek
irewall. > Watch out for the size of /var/log/packets: I will just add the appropriate stuff to logrotate (much as I am doing now for messages). > > # touch /var/log/packets > # echo "kern.debug/var/log/packets" >> /etc/syslog.conf > # /sbin/iptables -A INPUT

Re: ULOGD and iptables -j ULOG?

2003-03-26 Thread Miguel M
"kern.debug/var/log/packets" >> /etc/syslog.conf # /etc/init.d/syslog restart # /sbin/iptables -P INPUT ACCEPT # /sbin/iptables -P OUTPUT ACCEPT # /sbin/iptables -P FORWARD ACCEPT # /sbin/iptables -F ; /sbin/iptables -X # /sbin/iptables -A INPUT -j LOG --log-level DEBUG # /usr/bin/

ULOGD and iptables -j ULOG?

2003-03-26 Thread Mike Vanecek
I would like to log iptable -j LOG to something like local5 rather than to messages. However, based on my reading of the doco I do not see a way to change the logging facility for iptables. The iptables man talks about a -j ULOG. However, searches for information on how to use it (with specific

iptables (netfilter) mailing list ?

2003-03-24 Thread Allan M. Stewart
I've tried several times to get on the netfilter mailing list, but the confirmation never works. Is that mailing list still active? Is this or another place the best place for iptables questions? Thanks, Allan -- Psyche-list mailing list [EMAIL PROTECTED] https://listman.redha

SV: SV: Problem with Iptables// SOLVED

2003-03-13 Thread Tomas Larsson
ivirus 2K2. > -Ursprungligt meddelande- > Från: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] För Jack Bowling > Skickat: den 13 mars 2003 17:26 > Till: [EMAIL PROTECTED] > Ämne: Re: SV: Problem with IPtables > > > ** Reply to message from Tomas Larsson > &l

Re: SV: Problem with IPtables

2003-03-13 Thread Jack Bowling
your default FORWARD policy? If it is DROP then you need to specifically allow packets both ways. /sbin/iptables -L -v -n | grep FORWARD jb -- Jack Bowlingmailto:[EMAIL PROTECTED] Prince George, BC -- Psyche-list mailing list [EMAIL PROTECTED] https://listman.redhat.com/mailman/listinfo/psyche-list

Re: SV: Problem with IPtables

2003-03-13 Thread Mike Vanecek
I can connect to Apache from within internal network with internal > IP or host I can connect to external web servers. > > Everything is working > > Except > > I cannot connect to apache with domain or external IP > > When I do a iptables -L -v -n (-t nat) I can see

SV: Problem with IPtables

2003-03-13 Thread Tomas Larsson
ernal web servers. Everything is working Except I cannot connect to apache with domain or external IP When I do a iptables -L -v -n (-t nat) I can see that packets are forwarded to Apache, but nothing more happens. Is there something more and obvious I am missing With best regards Tomas La

Re: Problem with IPtables

2003-03-12 Thread J. M. Brenner
"Tomas Larsson" <[EMAIL PROTECTED]> wrote: > I have some problems setting up iptables. > Background: RH8 box as firewall and router. > Second RH8 box as apache server > I can reach the www-server from the internal network, but not from internet. I

Re: Problem with IPtables

2003-03-12 Thread jdow
From: "Tomas Larsson" <[EMAIL PROTECTED]> > $IPTABLES -A INPUT -i lo -s $UNIVERSE -d $UNIVERSE -j ACCEPT > $IPTABLES -A INPUT -i $INTIF -s $INTNET -d $UNIVERSE -j ACCEPT > $IPTABLES -A INPUT -i $EXTIF -s $INTNET -d $UNIVERSE -j drop-and-log-it > $IPTABLES -A INPUT -i

Problem with IPtables

2003-03-12 Thread Tomas Larsson
Hi group. I have some problems setting up iptables. Background: RH8 box as firewall and router. Second RH8 box as apache server I can reach the www-server from the internal network, but not from internet. My script looks basically like this, what am I missing? $IPTABLES -A INPUT

Re: IPTABLES question

2003-02-25 Thread Michael Schwendt
nished? > > To make it more permanent, put in /etc/sysconfig/iptables something like > this (note the default policy is drop, and packets are logged so you can > see who's being bounced). - -snip- Editing /etc/sysconfig/iptables is not such a good idea because it might trigger bug

Re: Re[2]: IPTABLES question

2003-02-24 Thread Ed . Greshko
e reasons I prefer to use shorewall. Well documented frontend to iptables. Doesn't forget a "key ingredient" (as my Grandmother used to do with her cookies). No need to learn the syntax yet you have every opportunity to learn about security. And, it has the facility to

Re: Re[2]: IPTABLES question

2003-02-24 Thread Jesse Keating
On Monday 24 February 2003 14:02, Jack Bowling wrote: > U, guys. No way these rules are going to work without a jump target. > So add: > > -j ACCEPT > > to the end of both given rules. Whoops! I knew I was forgetting something (; -- Jesse Keating RHCE MCSE http://geek.j2solutions.net Mondo

Re: Re[2]: IPTABLES question

2003-02-24 Thread Jack Bowling
On Mon, Feb 24, 2003 at 12:45:46PM -0800, Jesse Keating wrote: > On Monday 24 February 2003 12:43, Hans Scheffers wrote: > > Hello Jesse, > > What about outgoing? > > > > iptables -a OUTPUT -p tcp --sport 80 -d XXX.XXX.XXX.XXX > > maybe even including state=ESTABLI

Re: IPTABLES question

2003-02-24 Thread Iain Buchanan
On Tue, 2003-02-25 at 03:19, Leonard Miller wrote: > How do I allow incoming http port 80 from only one machine and > deny all others? Is it easy to turn off when testing is finished? To make it more permanent, put in /etc/sysconfig/iptables something like this (note the default policy i

Re: Re[2]: IPTABLES question

2003-02-24 Thread Jesse Keating
On Monday 24 February 2003 12:43, Hans Scheffers wrote: > Hello Jesse, > What about outgoing? > > iptables -a OUTPUT -p tcp --sport 80 -d XXX.XXX.XXX.XXX > maybe even including state=ESTABLISHED? I suppose you should add that. Not all firewalls block outgoing traffic, just incom

Re[2]: IPTABLES question

2003-02-24 Thread Hans Scheffers
Hello Jesse, What about outgoing? iptables -a OUTPUT -p tcp --sport 80 -d XXX.XXX.XXX.XXX maybe even including state=ESTABLISHED? Monday, February 24, 2003, 6:57:17 PM, you wrote: JK> On Monday 24 February 2003 09:49, Leonard Miller wrote: >> How do I allow incoming http port 80 from

Re: IPTABLES question

2003-02-24 Thread Jesse Keating
On Monday 24 February 2003 09:49, Leonard Miller wrote: > How do I allow incoming http port 80 from only one machine and > deny all others? Is it easy to turn off when testing is finished? iptables -a INPUT -p tcp --dport 80 -s XXX.XXX.XXX.XXX Where XXX.XXX.XXX.XXX is the IP of the machi

IPTABLES question

2003-02-24 Thread Leonard Miller
Hi, This was just dumped on my shoulders, so I'm coming here for help. I have not used iptables yet, although it is on my To-Do list. I have a test box and one of my co-horts wanted to test I-chain and asked me to allow incoming port 80 only from one address. I looked briefly at the doc

Re: Iptables rules for SAMBA

2003-02-19 Thread Antonio Montagnani
Iain Buchanan wrote: The best thing to do when debugging services that fail due to firewalls is to add a logging rule just before any reject/drop rules. Make your log rule match the same as the following REJECT rule, then you can watch your logs while you try to connect and see why its failing.

Re: Iptables rules for SAMBA

2003-02-19 Thread Iain Buchanan
On Wed, 2003-02-19 at 00:42, Antonio Montagnani wrote: > I built the iptables file with Lokkit and I added only the masquerading > line...everything is o.k. on my network: then added > the lines that should have made shares available between my firewalled > machine (192.168.0.1)

DNS and iptables

2003-02-18 Thread Quillen, Channon
I noticed that I wasn’t able to connect to RHN and was able to troubleshoot the problem down to a DNS problem.  However, I’m able to ping the DNS IP’s.  I’m not able to dig them though.   I thought the problem might be with iptables, so I tried to flush it by: #iptables –F   I get

Re: Iptables rules for SAMBA

2003-02-18 Thread Antonio Montagnani
Carlo Borelli wrote: You must specify in your rules what interfaces are you using. Ciao. I built the iptables file with Lokkit and I added only the masquerading line...everything is o.k. on my network: then added the lines that should have made shares available between my firewalled

RE: Iptables rules for SAMBA

2003-02-18 Thread Carlo Borelli
You must specify in your rules what interfaces are you using. Ciao. > I built the iptables file with Lokkit and I added only the > masquerading > line...everything is o.k. on my network: then added > the lines that should have made shares available between my > firewa

Iptables rules for SAMBA

2003-02-18 Thread Antonio Montagnani
I built the iptables file with Lokkit and I added only the masquerading line...everything is o.k. on my network: then added the lines that should have made shares available between my firewalled machine (192.168.0.1) and my other machine (192.168.0.10). What is wrong??? as I cannot share what I

Re: iptables

2003-02-15 Thread Michael Schwendt
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Sat, 15 Feb 2003 00:28:10 -0500 (EST), Justin Zygmont wrote: > does anyone have a basic ip masquerading script that they use in > /etc/sysconfig/iptables. It cannot set ip forwarding from there. What have you tried? /etc/sysconfig/iptab

iptables

2003-02-14 Thread Justin Zygmont
does anyone have a basic ip masquerading script that they use in /etc/sysconfig/iptables. It cannot set ip forwarding from there. -- Psyche-list mailing list [EMAIL PROTECTED] https://listman.redhat.com/mailman/listinfo/psyche-list

iptables blocking client NFS access

2003-02-06 Thread Ronald W. Heiby
Hello psyche-list, I've got a couple of RH 8.0 systems on a network. On one of these, I've set up a couple of entries in /etc/exports and set up NFS. On this (server) machine, I have opened up the iptables firewall to allow incoming tcp/udp ports 111 and 2049. On another (client) sy

Re: iptables strangeness

2003-02-02 Thread Michael Schwendt
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Sat, 1 Feb 2003 15:06:22 -0800, Charles A. Crayne wrote: > :I don't have a stock Psyche machine for testing here, but I cannot > :reproduce anything like that with Valhalla or updated Phoebe 8.0.93 > :or Psyche's iptabl

Re: iptables strangeness

2003-02-01 Thread Tommy McNeely
thats because of the format of /etc/sysconfig/iptables is not a script.. it is the format generated by iptables-save.. make the top part (the *nat) section of /etc/sysconfig/iptables look similar to the following to make it work "properly" :) *nat :PREROUTING ACCEPT [0:0] :POSTROUT

Re: iptables strangeness

2003-02-01 Thread Justin Clacherty
I had a similar problem a year or two ago. It's a bit hazy but from what I remember the iptables script wouldn't run if put in /etc/sysconfig/iptables, I actually had to run it separately after networking had been brought up (ran from rc.local I think). All I could put it down to was t

Re: iptables strangeness

2003-02-01 Thread Charles A. Crayne
On Sat, 1 Feb 2003 21:33:06 +0100 Michael Schwendt <[EMAIL PROTECTED]> wrote: :I don't have a stock Psyche machine for testing here, but I cannot :reproduce anything like that with Valhalla or updated Phoebe 8.0.93 :or Psyche's iptables-1.2.6a-3 package installed on Phoebe. Th

Re: iptables strangeness

2003-02-01 Thread Michael Schwendt
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Sat, 1 Feb 2003 11:53:33 -0800, Charles A. Crayne wrote: > :If the file /lib/iptables/libipt_MASQUERADE.so is not missing and > :the same rule is accepted on the command-line, find out a > :reproducible test-case. > > My t

Re: iptables strangeness

2003-02-01 Thread Charles A. Crayne
On Sat, 1 Feb 2003 16:01:19 +0100 Michael Schwendt <[EMAIL PROTECTED]> wrote: :If the file /lib/iptables/libipt_MASQUERADE.so is not missing and :the same rule is accepted on the command-line, find out a :reproducible test-case. My test case is 100% reproducible. :Try shortening your scr

Re: iptables strangeness

2003-02-01 Thread Michael Schwendt
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Fri, 31 Jan 2003 19:11:14 -0800, jdow wrote: > > In building a script for my iptables commands, I find that if I > > enter the command: > > > > iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -o ppp+ -j > > MASQ

Re: iptables strangeness

2003-01-31 Thread Charles A. Crayne
On Fri, 31 Jan 2003 19:11:14 -0800 "jdow" <[EMAIL PROTECTED]> wrote: :Yeah, is the ipchains emulation turned off and expunged from your system? Yes -- any other thoughts? -- Chuck -- Psyche-list mailing list [EMAIL PROTECTED] https://listman.redhat.com/mailman/listinfo/psyche-list

Re: iptables strangeness

2003-01-31 Thread jdow
From: "Charles A. Crayne" <[EMAIL PROTECTED]> > In building a script for my iptables commands, I find that if I enter > the command: > > iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -o ppp+ -j MASQUERADE > > from a command prompt, then it executes correct

iptables strangeness

2003-01-31 Thread Charles A. Crayne
In building a script for my iptables commands, I find that if I enter the command: iptables -t nat -A POSTROUTING -s 192.168.0.0/24 -o ppp+ -j MASQUERADE from a command prompt, then it executes correctly, but if I place the identical command into a file and invoke it as a script, then it fails

Re: Newest Iptables Again! :(

2003-01-31 Thread David Durst
;> > I send this question again if is possible to anyone help me. or if >> is possble. >> > >> > > Hi, Me AGAIN and my iptables problem.! :( >> > > >> > > again description my net and my problem. >> > > >> > > Have a

Re: Newest Iptables Again! :(

2003-01-31 Thread Pablo Allietti
ble to anyone help me. or if is > > possble. > > > > > Hi, Me AGAIN and my iptables problem.! :( > > > > > > again description my net and my problem. > > > > > > Have a 200.40.226.64 /28 net *public NET > > > have a 192.168.1.0 /24 n

Re: Newest Iptables Again! :(

2003-01-30 Thread Oeystein Olsen
On Wednesday 29 January 2003 09:38, Pablo Allietti wrote: > I send this question again if is possible to anyone help me. or if is > possble. > > > Hi, Me AGAIN and my iptables problem.! :( > > > > again description my net and my problem. > > > > Have a 200.4

Newest Iptables Again! with -L :(

2003-01-29 Thread Pablo Allietti
On Wed, Jan 29, 2003 at 08:21:48AM -0800, Jack Bowling wrote: > From: Jack Bowling <[EMAIL PROTECTED]> > Subject: Re: Newest Iptables Again! :( > To: [EMAIL PROTECTED] > X-Mailer: The Polarbar Mailer; version=1.25rc3; build=1953 > X-BeenThere: [EMAIL PROTECTED] > X-Mailma

Re: Newest Iptables Again! :(

2003-01-29 Thread Jack Bowling
** Reply to message from Pablo Allietti <[EMAIL PROTECTED]> on Wed, 29 Jan 2003 11:38:56 +0300 > I send this question again if is possible to anyone help me. or if is > possble. > > > > > > Hi, Me AGAIN and my iptables problem.! :( > > > > aga

Newest Iptables Again! :(

2003-01-29 Thread Pablo Allietti
I send this question again if is possible to anyone help me. or if is possble. > > Hi, Me AGAIN and my iptables problem.! :( > > again description my net and my problem. > > Have a 200.40.226.64 /28 net *public NET > have a 192.168.1.0 /24 net *private NET > >

Re: Iptables Again! :(

2003-01-28 Thread Pablo Allietti
> Have you created an alias eth0:0 on your external nic, for the second > external ip? > Yes, all function ok, but all clientes 192.168.1.x go outside with the server ip, this is the problem. > > > > > _ > The new MSN 8: sma

Iptables Again! :(

2003-01-28 Thread Jim Christiansen
Have you created an alias eth0:0 on your external nic, for the second external ip? _ The new MSN 8: smart spam protection and 2 months FREE* http://join.msn.com/?page=features/junkmail -- Psyche-list mailing list [EMAIL PROT

Iptables Again! :(

2003-01-28 Thread Pablo Allietti
Hi, Me AGAIN and my iptables problem.! :( again description my net and my problem. Have a 200.40.226.64 /28 net *public NET have a 192.168.1.0 /24 net *private NET have a 200.40.226.66 server running iptables * Is the gateway have a VoIp box THIS is the PROBLEM. i need to put behind the

Re: iptables netmask

2003-01-24 Thread Mike Vanecek
-- Original Message --- From: Jay Turner <[EMAIL PROTECTED]> To: [EMAIL PROTECTED] Sent: Fri, 24 Jan 2003 02:27:53 -0500 Subject: Re: iptables netmask > On Thu, Jan 23, 2003 at 07:12:31PM -0600, Mike Vanecek wrote: > > I am configuring RH 8 iptables. I have read

Re: iptables netmask

2003-01-24 Thread jdow
From: "Jay Turner" <[EMAIL PROTECTED]> > Would cover from 65.32.0.1 to 65.63.255.254 > > > > > Will ip address 64.255.0.0 trigger a hit? > > No. > > > > > Will ip address 65.55.1.1 trigger a hit? > > Yes. > > > > > How do I test the incoming source address against the above rule and determine > >

Re: iptables netmask

2003-01-23 Thread Jay Turner
On Thu, Jan 23, 2003 at 07:12:31PM -0600, Mike Vanecek wrote: > I am configuring RH 8 iptables. I have read several sources, but am still > unclear on the impact of a netmask on the source/destination definitions. > > For example, -s 65.50.0.0/11 would have a hit on what range of inco

iptables netmask

2003-01-23 Thread Mike Vanecek
I am configuring RH 8 iptables. I have read several sources, but am still unclear on the impact of a netmask on the source/destination definitions. For example, -s 65.50.0.0/11 would have a hit on what range of incoming packets? If I understand it correctly, which I really do not, the 11 means

Re: Iptables

2003-01-23 Thread Iain Buchanan
this do: 192.168.1.4 \ 192.168.1.5 --> 200.40.226.x 192.168.1.45/ > Its this possible with iptables or something and the inverse mode > too. You can do this with masquerading, through iptables. Established and related connections can get back in, and other connections can be

Re: Iptables

2003-01-23 Thread Markku Kolkka
92.168.1.45 ---> 200.40.226.75 > > Its this possible with iptables or something and the inverse mode > too. This is called NAT, see the NAT howto at http://www.iptables.org/documentation/index.html -- Markku Kolkka [EMAIL PROTECTED] -- Psyche-list mailing list [E

Iptables

2003-01-23 Thread Pablo Allietti
8.1.45 ---> 200.40.226.75 Its this possible with iptables or something and the inverse mode too. When in other network make a ssh 200.40.226.99 go to 192.168.1.4 Thanks a lot -- Psyche-list mailing list [EMAIL PROTECTED] https://listman.redhat.com/mailman/listinfo/psyche-list

Re: NFS server + iptables == pain

2003-01-20 Thread David Durst
> -A RH-Lokkit-0-50-INPUT -p tcp -m tcp --dport 111 --syn -j ACCEPT I believe you will need to remove the above rule and replace it w/ these two following rules. -A RH-Lokkit-0-50-INPUT -i -p tcp -m tcp --dport nfs -j ACCEPT -A RH-Lokkit-0-50 INPUT -p -p tcp -m tcp --dport sunrpc -j ACCEPT You

NFS server + iptables == pain

2003-01-20 Thread Alexander J. Marsh
Hello I am using an RH8 box as an NFS server. The clients are a combination of Solaris 8 and RH7.2-8. The NFS server works great when iptables is turned off, but not when its on. What ports need to be open to make this work. I have included my /etc/sysconfig/iptables file below. Any

Iptables

2003-01-16 Thread vasyl
Hi, all! Thanks to everyone with replies to my question about iptables! I'm new in Linux world and know not much. Vasyl -- Psyche-list mailing list [EMAIL PROTECTED] https://listman.redhat.com/mailman/listinfo/psyche-list

Re: Iptables

2003-01-16 Thread Michael Schwendt
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Thu, 16 Jan 2003 10:38:58 +0700, David Sudjiman wrote: > # Default Policy I/O DROP > iptables -P INPUT DROP > iptables -P OUTPUT DROP > > # Rules > iptables -A INPUT -i eth0 -p tcp -d your_ip --dport 80 -j ACCEPT > iptables

Re: Iptables

2003-01-15 Thread David Sudjiman
# Default Policy I/O DROP iptables -P INPUT DROP iptables -P OUTPUT DROP # Rules iptables -A INPUT -i eth0 -p tcp -d your_ip --dport 80 -j ACCEPT iptables -A OUTPUT -o eth0 -p tcp -d your_ip --dport 80 -j ACCEPT thx .dave ps. I'm not really sure about what you ask for - Original Me

Iptables

2003-01-15 Thread vasyl
Hi! How can I using iptables deny anything incoming and outgoing except port 80 for Internet and Apache? Thanks! Vasyl -- Psyche-list mailing list [EMAIL PROTECTED] https://listman.redhat.com/mailman/listinfo/psyche-list

Re: Lokkit (iptables) and DNS updates

2003-01-09 Thread Dennis Gilmore
using lokkit you will need to do custom setting and let in access to tcp port 53 to allow dns to work Dennis On Thu, 2003-01-09 at 00:30, Bret Chrismer wrote: > I have a new machine (Redhat 8.0) that I am trying to get working as a > primary DNS machine, but also wanting to use iptables t

RE: Lokkit (iptables) and DNS updates

2003-01-08 Thread Cowles, Steve
> -Original Message- > From: Bret Chrismer > Sent: Wednesday, January 08, 2003 8:31 AM > Subject: Lokkit (iptables) and DNS updates > > > I have a new machine (Redhat 8.0) that I am trying to get working > as a primary DNS machine, but also wanting to use iptables

Lokkit (iptables) and DNS updates

2003-01-08 Thread Bret Chrismer
I have a new machine (Redhat 8.0) that I am trying to get working as a primary DNS machine, but also wanting to use iptables to help secure the box.  One issue that I am having is that when iptables is running, the primary machine denies access to DNS services to all machines.  If I take

Re: iptables help

2002-12-26 Thread Ben Brown
Usually, you have to specify the interface. For example, I run a caching-only nameserver on my firewall that I don't want anyone to be able to query from outside the firewall, so I run this command: iptables -A INPUT -i eth0 -p tcp --dport 53 -j DROP Hope that syntax helps. Might also wa

iptables help

2002-12-23 Thread JUSTIN GERRY
I am attempting to create a iptables firewall for a server with two ethernet cards/two ip addresses. It is just your average webserver that has two domain names/webpages in it (virtual hosting with Apache). I can get iptables to work with one ip address, but not the 2nd one. It seems to ignore

Re: nfs client conflicts with iptables on my computer.

2002-12-16 Thread Gordon Messmer
On Mon, 2002-12-16 at 01:13, Deng Guang wrote: > When iptables is up, my computer can't mount remote fs.The error message > is "RPC time out". After I stop it, nfs client works fun. I deleted some > rules one by one to find which rule blocked the access. The result is >

RE: nfs client conflicts with iptables on my computer.

2002-12-16 Thread Paul Hamm
Psyche default firewalling is a bit brut force. I would recommend using one of the iptables scripts available on the net. I like gShield, shorewall gets some good press also. As far as which ports you should open do a google search on "common tcp ports nfs" In the case of nfs I belie

nfs client conflicts with iptables on my computer.

2002-12-16 Thread Deng Guang
When iptables is up, my computer can't mount remote fs.The error message is "RPC time out". After I stop it, nfs client works fun. I deleted some rules one by one to find which rule blocked the access. The result is the rule of 0:1023 port udp rejection. I am anxious to know whi

Re: Iptables Again jeje

2002-12-12 Thread Indrajit Raychaudhuri
I think you really mean to have 192.168.1.76 and 192.168.1.79 (instead of 192.164.1.76 and 192.164.1.79 respectively), don't you? Assuming that, and assuming you have PUBLIC_INTERFACE=, you need to have: iptables --table nat --append POSTROUTING --out-interface ${PUBLIC_INTERFACE} --s

Iptables Again jeje

2002-12-12 Thread Pablo Allietti
Pablo: I have a private nework with dhcp, 192.168.1.1 i need thats my clients give internet acces with diferents reals ips. examples the client 192.164.1.76 go outside with 200.40.197.68 the client 192.164.1.79 go outside with 200.40.197.69 -- Psyche-list mailing list [EMAIL PROTECTED] https:

Re: iptables logging

2002-12-11 Thread Iain Buchanan
On Thu, 2002-12-12 at 02:20, Bill Rugolsky Jr. wrote: > On Mon, Dec 02, 2002 at 11:34:54AM +0930, Iain Buchanan wrote: > > I've got iptables to log what it drops with various options, but its > > filling up my log files (theres a lot of traffic at work). Can I > > someh

Re: Iptables POOL real address

2002-12-11 Thread Ben Brown
You can simply run /sbin/iptables -t nat -A POSTROUTING -o eth0 -s 192.168.1.0/24 -j MASQUERADE If you want something a little more robust, you can check out http://www.xthorsworld.com/rc.firewall On Wed, 11 Dec 2002, Pablo Allietti wrote: > How is the method to configure iptables for m

Iptables POOL real address

2002-12-11 Thread Pablo Allietti
How is the method to configure iptables for make a conecction between my private network 192.168.1.1/24 to have internet access from my 200.40.197.66/28 in resuming need to make nat with a pool of real address. Thanks and sorry for my wnglish -- Psyche-list mailing list [EMAIL PROTECTED

Re: iptables logging

2002-12-11 Thread Bill Rugolsky Jr.
On Mon, Dec 02, 2002 at 11:34:54AM +0930, Iain Buchanan wrote: > I've got iptables to log what it drops with various options, but its > filling up my log files (theres a lot of traffic at work). Can I > somehow get it to log to a file other than /var/log/messages? Look into the UL

Re: Need Help IPTABLES RH8

2002-12-08 Thread David Sudjiman
CCEPT > -A INPUT -p tcp -m tcp --dport 443 --syn -j ACCEPT > -A INPUT -p udp --sport 137 --dport 137 -j DROP > > and > > /sbin/iptables --table nat --delete-chain > /sbin/iptables --table nat --append POSTROUTING --out-interface eth0:0 > -j MASQUERADE > /sbin/iptables --appe

Re: iptables interface eth0:1 does not work

2002-12-06 Thread Kevin McConnell
> Begin of Quote Hidemasa Yamakawa : > >Hi, all, > > > >I assigned 2 ip address to one ethernet card. > >One is eth0 and another is eth0:1. > >INPUT and FORWARD policy is DROP > >When I input > >iptables -A INPUT -i eth0:1 -j ACCEPT > >I got war

Re: iptables interface eth0:1 does not work

2002-12-06 Thread jdow
r is eth0:1. > > INPUT and FORWARD policy is DROP > > When I input > > iptables -A INPUT -i eth0:1 -j ACCEPT > > I got warning > > Warning: wierd character in interface `eth0:1' (No aliases, :, ! or *). > > and no packet come through this interface. > &g

Re: iptables interface eth0:1 does not work

2002-12-06 Thread Tommy McNeely
e: Hi, all, I assigned 2 ip address to one ethernet card. One is eth0 and another is eth0:1. INPUT and FORWARD policy is DROP When I input iptables -A INPUT -i eth0:1 -j ACCEPT I got warning Warning: wierd character in interface `eth0:1' (No aliases, :, ! or *). and no packet come through thi

Re: Need Help IPTABLES RH8

2002-12-06 Thread Tommy McNeely
check the ipv4 foward line in /etc/sysctl.conf it needs to be changed from 0 -> 1 then run "sysctl -p" Tommy --On Tuesday, December 03, 2002 07:05:49 PM -0500 Pablo Allietti <[EMAIL PROTECTED]> wrote: Hi i have a problem with iptables in RH8. I still have a firew

Re: iptables interface eth0:1 does not work

2002-12-06 Thread Tom Eastep
--On Friday, December 06, 2002 10:16:19 AM -0500 Hidemasa Yamakawa <[EMAIL PROTECTED]> wrote: Hi, all, I assigned 2 ip address to one ethernet card. One is eth0 and another is eth0:1. INPUT and FORWARD policy is DROP When I input iptables -A INPUT -i eth0:1 -j ACCEPT I got warning W

Re: iptables interface eth0:1 does not work

2002-12-06 Thread Roger
Around Fri,Dec 06 2002, at 10:16, Hidemasa Yamakawa, wrote: > Hi, all, > > I assigned 2 ip address to one ethernet card. > One is eth0 and another is eth0:1. > INPUT and FORWARD policy is DROP > When I input > iptables -A INPUT -i eth0:1 -j ACCEPT > I got warning >

Re: iptables interface eth0:1 does not work

2002-12-06 Thread Jack Bowling
** Reply to message from Hidemasa Yamakawa <[EMAIL PROTECTED]> on Fri, 06 Dec 2002 10:16:19 -0500 > Hi, all, > > I assigned 2 ip address to one ethernet card. > One is eth0 and another is eth0:1. > INPUT and FORWARD policy is DROP > When I input > iptables -A INPUT

Re: iptables interface eth0:1 does not work

2002-12-06 Thread Josep M.
Hi! Try sepparately for each ETH card or not put "-i" parameter. Josep Begin of Quote Hidemasa Yamakawa : >Hi, all, > >I assigned 2 ip address to one ethernet card. >One is eth0 and another is eth0:1. >INPUT and FORWARD policy is DROP >When I input >iptables -

iptables interface eth0:1 does not work

2002-12-06 Thread Hidemasa Yamakawa
Hi, all, I assigned 2 ip address to one ethernet card. One is eth0 and another is eth0:1. INPUT and FORWARD policy is DROP When I input iptables -A INPUT -i eth0:1 -j ACCEPT I got warning Warning: wierd character in interface `eth0:1' (No aliases, :, ! or *). and no packet come through

Need Help IPTABLES RH8

2002-12-06 Thread Pablo Allietti
Hi i have a problem with iptables in RH8. I still have a firewall function in rh7 but in the time to upgrade to 8, the machines behind a firewall dont access to INTERNET. my private network dont have access to outside. This is my old iptables please help me -A FORWARD -j ACCEPT -i eth0 -o

Re: iptables command

2002-12-02 Thread Jesse Keating
On Monday 02 December 2002 23:41, Joshua Melbourne White uttered: > I see many references to running the command iptables. However, when I > try to do that in the terminal window, it says it isnt a command. The > iptables service is running however... Any suggestions? Yes, use (su -)

  1   2   3   >