Re: ntp issues
Chris Wensink <cwensink-vkMKHgLPN8f9Ak/[email protected]> Fri, 21 Jul 2017 16:27:05 -0500
| Newsgroups | gmane.comp.security.ipcop.user |
|---|---|
| Message-ID | <[email protected]> |
Thanks for the advice, I'll set up a new installation of ipcop and work from that. I'm 80% there already with another lower end PC. Chris On 7/21/2017 2:11 PM, G.W. Haywood wrote: > Hello again, > > On Fri, 21 Jul 2017, Chris Wensink wrote: > >> During the windows request this is what shows up in /var/log/messages: >> >> Jul 21 10:56:24 ipcop kernel: RED ACCEPT IN=wan-1 OUT= >> MAC=0c:c4:7a:01:dd:ae:50:87:89:e6:f6:80:08:00 SRC=46.243.26.34 >> DST=X.X.X.X LEN=76 TOS=0x00 PREC=0x00 TTL=116 ID=23488 PROTO=UDP >> SPT=123 DPT=123 LEN=56 > > Please keep correspondence on the list, so that others get a chance to > see it. By all means redact the public IP address, especially in view > of the state of the firewall rules which are in a pretty terrible mess. > On a quick glance I don't see an obvious block for NTP packets in what > you sent. Quite the reverse in fact, there seem to be a few redundant > rules - some of them ACCEPT for all packets which is a bit terrifying. > That may be from your frenetically adding rules in an attempt to get > the time service working. There is *nothing* in the CUSTOMFORWARD, > CUSTOMINPUT and CUSTOMOUTPUT chains, the places where I'd expect to > see the bulk of your customisations. That's what they're for. > > But you've only sent the 'filter' table contents; when you post again > (to the list, please), include the contents of all the tables and not > just the filter table. Look at 'man iptables' on one of your Linux > boxes for more about the few tables that there are. I suspect that it > might be something in the 'nat' table which is causing your problems. > My reasoning is that in the log extract that I've quoted above, there > is an interface name (wan-1) given after 'IN=', but after 'OUT=', no > interface name is given where I would expect the interface name of the > GREEN interface. This makes me think that IPCop doesn't know that it > should be forwarding the packets to its Windows client, and is instead > passing them to itself - and then dropping them. > > I'm tempted to suggest you reinstall IPCop from scratch, to start from > some kind of a stable base for the firewall rules. It would take me a > good while to go through all your rules as they are and fix them up to > be sure that they're safe against malicious parties; it would be a lot > easier to start from scratch, even if I wrote the rules by hand. > > Incidentally when I look at iptables rules I have a sort of "command of > thumb" that I almost always use to see them: > > iptables -L -v -n --line-numbers --exact | less -S > > This shows (for the default 'filter' table in this case) the number of > packets and bytes each rule has seen, and it also numbers the lines in > the chains so you can more easily refer to them. For example you might > want to replace them, or delete them, or '-I' another rule just before > or just after them in the chain. Quite often I do that temporarily, > often rules which do nothing but count packets (or particular kinds of > packets) as they traverese the chains. NTP packets for example. :) I > recommend both techniques for troubleshooting iptables rulesets. > > 73, > Ged. > > ------------------------------------------------------------------------------ > > Check out the vibrant tech community on one of the world's most > engaging tech sites, Slashdot.org! http://sdm.link/slashdot > _______________________________________________ > IPCop-user mailing list > [email protected] > Manage your subscription or unsubscribe > https://lists.sourceforge.net/lists/listinfo/ipcop-user -- Christopher Wensink IS Administrator Five Star Plastics, Inc 1339 Continental Drive Eau Claire, WI 54701 Office: 715-831-1682 Mobile: 715-563-3112 Fax: 715-831-6075 cwensink-vkMKHgLPN8f9Ak/[email protected] www.five-star-plastics.com ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot _______________________________________________ IPCop-user mailing list [email protected] Manage your subscription or unsubscribe https://lists.sourceforge.net/lists/listinfo/ipcop-user