Re: Firewall issues
Trey Gruel <[email protected]>
| Newsgroups | gmane.linux.redhat.release.enigma |
|---|---|
| Message-ID | <[email protected]> |
Keith Mastin wrote:
>>I've set up a iptables firewall on my RH7.2 box, but I'm running into an
>> odd problem. After I set up the firewall, everything works fine for a
>>few hours. But after a while (not sure the exact amount of time), the
>>computer stops responding to requests on the open ports. Looking at the
>> output from iptables -vL, I can see the requests coming in and passing
>>the appropriate rule, but then nothing happens (almost as if the packet
>>is dropped). Here is the firewall as I have it set up:
>
>
> check your ethernet configs.... look for improper mtu (should be about
> 1492 if your on dsl, 1500 on dialup or cable) or improper duplex mode. The
> firewall should not be causing what appear to be timeouts.
ip link shows the following:
1: lo: <LOOPBACK,UP> mtu 16436 qdisc noqueue
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
2: eth0: <BROADCAST,UP> mtu 1500 qdisc pfifo_fast qlen 100
link/ether 00:90:27:dc:46:2a brd ff:ff:ff:ff:ff:ff
3: eth1: <BROADCAST,NOTRAILERS,UP> mtu 1500 qdisc pfifo_fast qlen 100
link/ether 00:d0:b7:e4:d3:e3 brd ff:ff:ff:ff:ff:ff
I'm pretty sure this is on a T1 (noone in the office is 100% sure that's
what it is..)
> Also, have you checked your logs, and if so, what, if anything, so they
> tell you?
I see hits on other random ports (80, 1080, 1433, etc..) that are
supposed to make it to the logdrop chain, but nothing shows up for the
ports I'm allowing. Any time I try to ssh, ftp, or ping the box from
the outside world, I can see the count go up for the correct rule.
I have also tried flushing the INPUT chain and setting the policy to
ACCEPT, but I'm still not getting any responses to requests from the
outside world.. Very confused..
--
Trey Gruel
[email protected]
703-713-1640 x320