Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #248501 > unrolled thread

Firewall blocking my new Debian 11 server ports 80 and 443

Started byTom Browder <tom.browder@gmail.com>
First post2022-05-28 21:20 +0200
Last post2022-05-29 00:30 +0200
Articles 20 on this page of 56 — 13 participants

Back to article view | Back to linux.debian.user


Contents

  Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-28 21:20 +0200
    Re: Firewall blocking my new Debian 11 server ports 80 and 443 Dan Ritter <dsr@randomstring.org> - 2022-05-28 21:40 +0200
    Re: Firewall blocking my new Debian 11 server ports 80 and 443 Georgi Naplatanov <gosho@oles.biz> - 2022-05-28 21:50 +0200
    Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-28 22:00 +0200
    Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-28 23:10 +0200
      Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 00:30 +0200
        Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 17:00 +0200
          Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 17:00 +0200
            Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 17:30 +0200
              Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 17:40 +0200
                Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 18:30 +0200
                  Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 18:40 +0200
                  Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 18:40 +0200
                    Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 19:30 +0200
                      Re: Firewall blocking my new Debian 11 server ports 80 and 443 john doe <johndoe65534@mail.com> - 2022-05-29 20:30 +0200
                        Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 21:00 +0200
                        Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-29 21:30 +0200
                          Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 22:50 +0200
                            Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-29 23:00 +0200
                              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-30 00:30 +0200
                                Re: Firewall blocking my new Debian 11 server ports 80 and 443 john doe <johndoe65534@mail.com> - 2022-05-30 09:20 +0200
                                  Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-30 14:20 +0200
                                    Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-30 15:50 +0200
                                      Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-30 16:10 +0200
                                        Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-30 19:30 +0200
                                          Re: Firewall blocking my new Debian 11 server ports 80 and 443 Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2022-05-31 01:00 +0200
                                      Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-30 19:30 +0200
                                      Re: Firewall blocking my new Debian 11 server ports 80 and 443 Edwin Zimmerman <edwin@plainemail.net> - 2022-05-31 02:50 +0200
                                        Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-06-01 13:50 +0200
                                          Re: Firewall blocking my new Debian 11 server ports 80 and 443 john doe <johndoe65534@mail.com> - 2022-06-01 18:30 +0200
                                            Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-06-01 19:20 +0200
                              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Lee <ler762@gmail.com> - 2022-05-30 02:00 +0200
                                Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-30 02:20 +0200
                                  Re: Firewall blocking my new Debian 11 server ports 80 and 443 Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2022-05-30 02:40 +0200
                                Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-30 02:30 +0200
                              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Curt <curty@free.fr> - 2022-05-30 14:10 +0200
      Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 00:30 +0200
        Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 00:40 +0200
          Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 01:00 +0200
            Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 02:00 +0200
              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2022-05-29 02:20 +0200
                Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 02:40 +0200
              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Charles Kroeger <mbone@gmx.co.uk> - 2022-05-30 07:30 +0200
            Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-29 02:10 +0200
              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 02:20 +0200
            Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 03:10 +0200
              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 04:00 +0200
              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 12:50 +0200
                Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 13:30 +0200
                  Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 14:10 +0200
                    Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 14:30 +0200
                      Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 14:50 +0200
                  Re: Firewall blocking my new Debian 11 server ports 80 and 443 Erwan David <erwan@rail.eu.org> - 2022-05-29 16:00 +0200
                Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 14:10 +0200
                Re: Firewall blocking my new Debian 11 server ports 80 and 443 <tomas@tuxteam.de> - 2022-05-29 19:00 +0200
      Re: Firewall blocking my new Debian 11 server ports 80 and 443 Dan Ritter <dsr@randomstring.org> - 2022-05-29 00:30 +0200

Page 2 of 3 — ← Prev page 1 [2] 3  Next page →


#248565

Fromjohn doe <johndoe65534@mail.com>
Date2022-05-30 09:20 +0200
Message-ID<EsHQZ-1hCE-9@gated-at.bofh.it>
In reply to#248550
On 5/30/2022 12:26 AM, Tom Browder wrote:
> On Sun, May 29, 2022 at 15:55 Greg Wooledge <greg@wooledge.org> wrote:
> ...
>
> Thanks, Greg. It looks like my server was blocked from ports 80 and 443
> upstream from it (as you and others suspected), so I asked my provider to
> reinstall the OS and ensure it has public access to ports 80 and 443.
>

If I may, looks like this is over your head and I would suggest you to
do the following:
- Understand what is done on this server (installed pkgs, config ...)
- Start by securing remote access (see this thread on to do that for SSH)
- Get all of your set up working offline/locally
- Document yourself on how to do what you want (when exposing services
publically you can not guess/try)


In other words, familiorise yourself with what you have.

--
John Doe

[toc] | [prev] | [next] | [standalone]


#248569

FromTom Browder <tom.browder@gmail.com>
Date2022-05-30 14:20 +0200
Message-ID<EsMxj-1kth-3@gated-at.bofh.it>
In reply to#248565

[Multipart message — attachments visible in raw view] — view raw

On Mon, May 30, 2022 at 02:13 john doe <johndoe65534@mail.com> wrote:

> On 5/30/2022 12:26 AM, Tom Browder wrote:
> > On Sun, May 29, 2022 at 15:55 Greg Wooledge <greg@wooledge.org> wrote:


No worries. All those responses about the subject IP now are the norm for a
bare-iron server ready for use by a customer, yours truly. It is the same
server I messed up the firewall with and locked myself out of. The OS has
been reinstalled and is ready for me to use again.

If all is set as expected, I should be able to get http and https working
on it.

And I will certainly try to take care of most of the security concerns
expressed here.

For those of you with forensic curiosity so recently demonstrated, the new
server we are discussing is to replace mine currently operating at IP
173.208.182.170. It has been online for over two years. I believe it is
locked down pretty well.

Some websites there are:

    novco1968tbs.com       # my Marine brother's TBS  class
    usafa-1965.org             # my college class
    moody67a.org               # my pilot training class
    nwflug.org
    computertechnwf.org

The first three sites have entries very appropriate for US Memorial Day:
noting men who sacrificed their lives fighting for us.

-Tom

[toc] | [prev] | [next] | [standalone]


#248574

FromGreg Wooledge <greg@wooledge.org>
Date2022-05-30 15:50 +0200
Message-ID<EsNWp-1lcG-5@gated-at.bofh.it>
In reply to#248569
On Mon, May 30, 2022 at 07:13:54AM -0500, Tom Browder wrote:
> No worries. All those responses about the subject IP now are the norm for a
> bare-iron server ready for use by a customer, yours truly. It is the same
> server I messed up the firewall with and locked myself out of. The OS has
> been reinstalled and is ready for me to use again.

Why are you installing a firewall on a web server *at all*?

The only thing you need to secure is your ssh access, and that's
usually done in the /etc/ssh/sshd_config file, either by setting
up key access only, or by restricting the source IPs who can connect.

The web service is supposed to be open to the whole world.  That's
why it's called the World Wide Web.

Unless this machine is more than just a web server...?

[toc] | [prev] | [next] | [standalone]


#248575

FromIL Ka <kazakevichilya@gmail.com>
Date2022-05-30 16:10 +0200
Message-ID<EsOfL-1lym-1@gated-at.bofh.it>
In reply to#248574

[Multipart message — attachments visible in raw view] — view raw

IMHO: It is better to have a firewall and block (policy -- drop) INPUT and
FORWARD by default.
And open only ports that must be opened.
This will help if you install some software that listens for 0.0.0.0 by
accident

On Mon, May 30, 2022 at 4:42 PM Greg Wooledge <greg@wooledge.org> wrote:

> On Mon, May 30, 2022 at 07:13:54AM -0500, Tom Browder wrote:
> > No worries. All those responses about the subject IP now are the norm
> for a
> > bare-iron server ready for use by a customer, yours truly. It is the same
> > server I messed up the firewall with and locked myself out of. The OS has
> > been reinstalled and is ready for me to use again.
>
> Why are you installing a firewall on a web server *at all*?
>
> The only thing you need to secure is your ssh access, and that's
> usually done in the /etc/ssh/sshd_config file, either by setting
> up key access only, or by restricting the source IPs who can connect.
>
> The web service is supposed to be open to the whole world.  That's
> why it's called the World Wide Web.
>
> Unless this machine is more than just a web server...?
>
>

[toc] | [prev] | [next] | [standalone]


#248583

FromTom Browder <tom.browder@gmail.com>
Date2022-05-30 19:30 +0200
Message-ID<EsRnj-1nqi-7@gated-at.bofh.it>
In reply to#248575

[Multipart message — attachments visible in raw view] — view raw

On Mon, May 30, 2022 at 09:03 IL Ka <kazakevichilya@gmail.com> wrote:

> IMHO: It is better to have a firewall and block (policy -- drop) INPUT and
> FORWARD by default.
> And open only ports that must be opened.
> This will help if you install some software that listens for 0.0.0.0 by
> accident
>

>From my limited research, that seems to be the prevailing view.

-Tom

[toc] | [prev] | [next] | [standalone]


#248594

FromTimothy M Butterworth <timothy.m.butterworth@gmail.com>
Date2022-05-31 01:00 +0200
Message-ID<EsWwF-1qno-1@gated-at.bofh.it>
In reply to#248583

[Multipart message — attachments visible in raw view] — view raw

On Mon, May 30, 2022 at 1:24 PM Tom Browder <tom.browder@gmail.com> wrote:

> On Mon, May 30, 2022 at 09:03 IL Ka <kazakevichilya@gmail.com> wrote:
>
>> IMHO: It is better to have a firewall and block (policy -- drop) INPUT
>> and FORWARD by default.
>> And open only ports that must be opened.
>> This will help if you install some software that listens for 0.0.0.0 by
>> accident
>>
>
> From my limited research, that seems to be the prevailing view.
>
> -Tom
>

If you have firewalld try running:
`firewall-cmd --permanent --add-service=http`
`firewall-cmd --reload`

[toc] | [prev] | [next] | [standalone]


#248582

FromTom Browder <tom.browder@gmail.com>
Date2022-05-30 19:30 +0200
Message-ID<EsRnj-1nqi-9@gated-at.bofh.it>
In reply to#248574

[Multipart message — attachments visible in raw view] — view raw

On Mon, May 30, 2022 at 08:42 Greg Wooledge <greg@wooledge.org> wrote:
..

> Unless this machine is more than just a web server...?


It does serve other purposes.

[toc] | [prev] | [next] | [standalone]


#248598

FromEdwin Zimmerman <edwin@plainemail.net>
Date2022-05-31 02:50 +0200
Message-ID<EsYf8-1rq9-3@gated-at.bofh.it>
In reply to#248574
On 5/30/22 09:41, Greg Wooledge wrote:
> On Mon, May 30, 2022 at 07:13:54AM -0500, Tom Browder wrote:
>> No worries. All those responses about the subject IP now are the norm for a
>> bare-iron server ready for use by a customer, yours truly. It is the same
>> server I messed up the firewall with and locked myself out of. The OS has
>> been reinstalled and is ready for me to use again.
> Why are you installing a firewall on a web server *at all*?
Because it prevents accidental port exposure.  It's not uncommon to be running some other service other than the web server, and accidental configurations happen all the time.  A firewall is a simple security measure to contain such problems.

[toc] | [prev] | [next] | [standalone]


#248626

FromTom Browder <tom.browder@gmail.com>
Date2022-06-01 13:50 +0200
Message-ID<Etv1n-1NCk-17@gated-at.bofh.it>
In reply to#248598

[Multipart message — attachments visible in raw view] — view raw

On Mon, May 30, 2022 at 19:46 Edwin Zimmerman <edwin@plainemail.net> wrote:

> On 5/30/22 09:41, Greg Wooledge wrote:
> > On Mon, May 30, 2022 at 07:13:54AM -0500, Tom Browder wrote:
> >> No worries. All those responses about the subject IP now are the norm
> for a
> >> bare-iron server ready for use by a customer, yours truly. It is the
> same
> >> server I messed up the firewall with and locked myself out of. The OS
> has
> >> been reinstalled and is ready for me to use again.


On that note, for my next try with the server, I will definitely use UFW
with the legacy uptables that was suggested.

But a question: it is clear that it must be enabled to go into effect, but
when does it actually start operating? Does it do so then, or does it take
a reboot?

-Tom

[toc] | [prev] | [next] | [standalone]


#248636

Fromjohn doe <johndoe65534@mail.com>
Date2022-06-01 18:30 +0200
Message-ID<Etzom-1Qfs-7@gated-at.bofh.it>
In reply to#248626
On 6/1/2022 1:45 PM, Tom Browder wrote:
> On Mon, May 30, 2022 at 19:46 Edwin Zimmerman <edwin@plainemail.net> wrote:
>
>> On 5/30/22 09:41, Greg Wooledge wrote:
>>> On Mon, May 30, 2022 at 07:13:54AM -0500, Tom Browder wrote:
>>>> No worries. All those responses about the subject IP now are the norm
>> for a
>>>> bare-iron server ready for use by a customer, yours truly. It is the
>> same
>>>> server I messed up the firewall with and locked myself out of. The OS
>> has
>>>> been reinstalled and is ready for me to use again.
>
>
> On that note, for my next try with the server, I will definitely use UFW
> with the legacy uptables that was suggested.
>
> But a question: it is clear that it must be enabled to go into effect, but
> when does it actually start operating? Does it do so then, or does it take
> a reboot?
>

Apparently, if you 'enable' 'ufw', it will start and be enabled at boot.

According to (1), ufw should work with nftables, I did not follow the
reasoning on why to use iptables but only if you have issues use legacy
iptables.

1)  https://wiki.archlinux.org/title/Uncomplicated_Firewall

--
John Doe

[toc] | [prev] | [next] | [standalone]


#248639

FromTom Browder <tom.browder@gmail.com>
Date2022-06-01 19:20 +0200
Message-ID<EtAaJ-1QKt-1@gated-at.bofh.it>
In reply to#248636

[Multipart message — attachments visible in raw view] — view raw

On Wed, Jun 1, 2022 at 11:21 john doe <johndoe65534@mail.com> wrote:

> when does it actually start operating? Does it do so then, or does it take
>
> a reboot?
>

Apparently, if you 'enable' 'ufw', it will start and be enabled at boot.


Good, thanks.

According to (1), ufw should work with nftables, I did not follow the
> reasoning on why to use iptables but only if you have issues use legacy
> iptables.
>

Well, the guidance I got was varying. In my mind, Il Ka seemed to be the
most well-informed and understanding of my specific needs, and I went with
his recommendations. He was upfront about why he stayed with iptables, and
I also favor that view. Based on my experience upgrading Debian since
version 4, I know I don't like to jump on new stuff right away, but expect
to have to eventually.

-Tom

[toc] | [prev] | [next] | [standalone]


#248553

FromLee <ler762@gmail.com>
Date2022-05-30 02:00 +0200
Message-ID<EsAZb-1dhy-3@gated-at.bofh.it>
In reply to#248548
On 5/29/22, Greg Wooledge <greg@wooledge.org> wrote:
> On Sun, May 29, 2022 at 03:39:05PM -0500, Tom Browder wrote:
>> I have not intentionally hidden anything, Greg--I just never saw the need
>> for
>> mentioning it given the dialogue--x.y.z.w is just shorthand. If you
>> must know the exact IP address, it is 69.30.225.10.
>
> OK.  Now we can actually start helping.
>
> First of all, this is a regular old routable IPv4 address.  It's not one
> of the non-routables, like 192.168.* or 10.*.  This is good.  It
> eliminates a whole class of problems like "My machine's IP address says
> 192.168.1.2 but I can't reach it from outside my network", all of which
> were still on the table until now.
>
> Second, I cannot ping this IP address, nor can I telnet to port 80 of it.

For whatever it's worth..

Pinging 69.30.225.10 with 32 bytes of data:
Reply from 69.30.225.10: bytes=32 time=43ms TTL=53
Reply from 69.30.225.10: bytes=32 time=42ms TTL=53
Reply from 69.30.225.10: bytes=32 time=43ms TTL=53
Reply from 69.30.225.10: bytes=32 time=42ms TTL=53

I had wireshark running while trying to telnet there and I get a RST ~
45ms after sending the SYN

ssh gives me a login prompt

Lee

[toc] | [prev] | [next] | [standalone]


#248554

FromGreg Wooledge <greg@wooledge.org>
Date2022-05-30 02:20 +0200
Message-ID<EsBix-1dCR-1@gated-at.bofh.it>
In reply to#248553
On Sun, May 29, 2022 at 11:50:44PM +0000, Lee wrote:
> On 5/29/22, Greg Wooledge <greg@wooledge.org> wrote:
> > Second, I cannot ping this IP address, nor can I telnet to port 80 of it.
> 
> For whatever it's worth..
> 
> Pinging 69.30.225.10 with 32 bytes of data:
> Reply from 69.30.225.10: bytes=32 time=43ms TTL=53
> Reply from 69.30.225.10: bytes=32 time=42ms TTL=53
> Reply from 69.30.225.10: bytes=32 time=43ms TTL=53
> Reply from 69.30.225.10: bytes=32 time=42ms TTL=53

Yes, it's working from here now, too.  Changes definitely happened
on the OP's server's side.

[toc] | [prev] | [next] | [standalone]


#248556

FromTimothy M Butterworth <timothy.m.butterworth@gmail.com>
Date2022-05-30 02:40 +0200
Message-ID<EsBBT-1dIv-1@gated-at.bofh.it>
In reply to#248554

[Multipart message — attachments visible in raw view] — view raw

On Sun, May 29, 2022 at 8:13 PM Greg Wooledge <greg@wooledge.org> wrote:

> On Sun, May 29, 2022 at 11:50:44PM +0000, Lee wrote:
> > On 5/29/22, Greg Wooledge <greg@wooledge.org> wrote:
> > > Second, I cannot ping this IP address, nor can I telnet to port 80 of
> it.
> >
> > For whatever it's worth..
> >
> > Pinging 69.30.225.10 with 32 bytes of data:
> > Reply from 69.30.225.10: bytes=32 time=43ms TTL=53
> > Reply from 69.30.225.10: bytes=32 time=42ms TTL=53
> > Reply from 69.30.225.10: bytes=32 time=43ms TTL=53
> > Reply from 69.30.225.10: bytes=32 time=42ms TTL=53
>
> Yes, it's working from here now, too.  Changes definitely happened
> on the OP's server's side.
>
> I did a TCPTraceRoute to your server on port 80 it makes it across all
hops but says the port is closed on the server.

tcptraceroute 69.30.225.10
Selected device wlo1, address 192.168.105.250, port 38109 for outgoing
packets
Tracing the path to 69.30.225.10 on TCP port 80 (http), 30 hops max
1  192.168.105.156  7.422 ms  3.828 ms  3.985 ms
2  17.sub-66-174-63.myvzw.com (66.174.63.17)  340.678 ms  692.027 ms
 185.134 ms
3  194.sub-69-83-70.myvzw.com (69.83.70.194)  107.194 ms  596.305 ms
 257.465 ms
4  * * *
5  242.sub-69-83-70.myvzw.com (69.83.70.242)  556.143 ms  57.157 ms  47.478
ms
6  * * *
7  * * *
8  * * *
9  153.sub-69-83-66.myvzw.com (69.83.66.153)  184.145 ms  61.027 ms  48.539
ms
10  * * *
11  * * *
12  * be3083.ccr41.dca01.atlas.cogentco.com (154.54.30.53) 445.471 ms
 97.201 ms
13  be2891.ccr21.cle04.atlas.cogentco.com (154.54.82.249)  106.103 ms * *
14  * * *
15  * * be2831.ccr21.mci01.atlas.cogentco.com (154.54.42.165) 96.672 ms
16  be2546.rcr01.b073673-0.mci01.atlas.cogentco.com (154.54.30.242)  97.542
ms  89.655 ms *
17  * * *
18  * * *
19  100ge13-1.edge-a.clay.as33387.net (69.30.209.195)  725.149 ms  578.818
ms  414.786 ms
20  * * *
21  * * *
22  * server.pcstar1.com (69.30.225.10) [closed] 379.939 ms  413.809 ms

[toc] | [prev] | [next] | [standalone]


#248555

FromIL Ka <kazakevichilya@gmail.com>
Date2022-05-30 02:30 +0200
Message-ID<EsBsd-1dFC-1@gated-at.bofh.it>
In reply to#248553

[Multipart message — attachments visible in raw view] — view raw

>
>
> ssh gives me a login prompt
>
>
Btw, I highly recommend:
* Block SSH access from any IP except one you are going to use to manage
this server
* If you have dynamic IP, you can add all your ISP network, or, at least,
your country: (list can be downloaded here
 https://blog.ip2location.com/knowledge-base/how-to-block-ip-addresses-from-a-country-using-ipset/
<https://blog.ip2location.com/knowledge-base/how-to-block-ip-addresses-from-a-country-using-ipset/>
)
* Deny password access and use keys only (use EdDSA, not RSA if possible).
Passwords should never be used
* Disable root access
* Get rid of SHA-1 and other weak things:
https://sshcheck.com/server/69.30.225.10/

You have your ssh server opened to the whole world and there are zillions
of bots trying to guess your password now.

[toc] | [prev] | [next] | [standalone]


#248568

FromCurt <curty@free.fr>
Date2022-05-30 14:10 +0200
Message-ID<EsMnE-1kpV-11@gated-at.bofh.it>
In reply to#248548
On 2022-05-29, Greg Wooledge <greg@wooledge.org> wrote:
>
> Second, I cannot ping this IP address, nor can I telnet to port 80 of it.
> (Nor port 22.)
>

That's strange; I can ping it (I'm not in Kansas anymore):

curty@einstein:~$ ping  69.30.225.10
PING 69.30.225.10 (69.30.225.10) 56(84) bytes of data.
64 bytes from 69.30.225.10: icmp_seq=1 ttl=51 time=110 ms
64 bytes from 69.30.225.10: icmp_seq=2 ttl=51 time=109 ms
64 bytes from 69.30.225.10: icmp_seq=3 ttl=51 time=110 ms
64 bytes from 69.30.225.10: icmp_seq=4 ttl=51 time=110 ms
64 bytes from 69.30.225.10: icmp_seq=5 ttl=51 time=109 ms
64 bytes from 69.30.225.10: icmp_seq=6 ttl=51 time=109 ms
^C
--- 69.30.225.10 ping statistics ---
6 packets transmitted, 6 received, 0% packet loss, time 5007ms
rtt min/avg/max/mdev = 109.920/110.172/110.613/0.511 ms

[toc] | [prev] | [next] | [standalone]


#248511

FromTom Browder <tom.browder@gmail.com>
Date2022-05-29 00:30 +0200
Message-ID<Esd6x-YVu-5@gated-at.bofh.it>
In reply to#248507

[Multipart message — attachments visible in raw view] — view raw

On Sat, May 28, 2022 at 17:08 Dan Ritter <dsr@randomstring.org> wrote:
…

Therefore, something outside of your machine is blocking the
> ports, or you are misreading or misusing the tools that are
> telling you the ports are blocked.


Tell us how you are checking the ports


I am running an Apache server and using Qualys Lab’s server checker. It
shows no access to the server.

And my server leasing company blocks no ports outside each host’s own
settings.

Whatever attempt I make to change the ports disappears when I reboot.

-Tom

[toc] | [prev] | [next] | [standalone]


#248513

FromIL Ka <kazakevichilya@gmail.com>
Date2022-05-29 00:40 +0200
Message-ID<Esdgd-YYq-9@gated-at.bofh.it>
In reply to#248511

[Multipart message — attachments visible in raw view] — view raw

>
> I am running an Apache server and using Qualys Lab’s server checker. It
> shows no access to the server.
>
> Have you tried to telnet to port 80 from home? Do you see apache
listening this port using ``ss``?



>
> Whatever attempt I make to change the ports disappears when I reboot.
>
> Sure, because you need netfilter-persistent (at least for iptables)



> -Tom
>

[toc] | [prev] | [next] | [standalone]


#248514

FromTom Browder <tom.browder@gmail.com>
Date2022-05-29 01:00 +0200
Message-ID<Esdzz-Z4r-1@gated-at.bofh.it>
In reply to#248513

[Multipart message — attachments visible in raw view] — view raw

On Sat, May 28, 2022 at 17:30 IL Ka <kazakevichilya@gmail.com> wrote:

> I am running an Apache server and using Qualys Lab’s server checker. It
>> shows no access to the server.
>>
>> Have you tried to telnet to port 80 from home? Do you see apache
> listening this port using ``ss``?
>

On the new host I did:

    $ sudo su
    # telnet 80
    Trying 0.0.0.80...


and gave up waiting.

[toc] | [prev] | [next] | [standalone]


#248515

FromTom Browder <tom.browder@gmail.com>
Date2022-05-29 02:00 +0200
Message-ID<EsevD-ZBp-3@gated-at.bofh.it>
In reply to#248514

[Multipart message — attachments visible in raw view] — view raw

On Sat, May 28, 2022 at 17:51 Tom Browder <tom.browder@gmail.com> wrote:

> On Sat, May 28, 2022 at 17:30 IL Ka <kazakevichilya@gmail.com> wrote:
>
>> I am running an Apache server and using Qualys Lab’s server checker. It
>>> shows no access to the server.
>>>
>>> Have you tried to telnet to port 80 from home? Do you see apache
>> listening this port using ``ss``?
>>
>
> On the new host I did:
>
>     $ sudo su
>     # telnet 80
>     Trying 0.0.0.80...
>
>
> and gave up waiting.
>

Maybe I should remove all firewall progs and start from zero.

[toc] | [prev] | [next] | [standalone]


Page 2 of 3 — ← Prev page 1 [2] 3  Next page →

Back to top | Article view | linux.debian.user


csiph-web