Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #248501 > unrolled thread

Firewall blocking my new Debian 11 server ports 80 and 443

Started byTom Browder <tom.browder@gmail.com>
First post2022-05-28 21:20 +0200
Last post2022-05-29 00:30 +0200
Articles 16 on this page of 56 — 13 participants

Back to article view | Back to linux.debian.user


Contents

  Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-28 21:20 +0200
    Re: Firewall blocking my new Debian 11 server ports 80 and 443 Dan Ritter <dsr@randomstring.org> - 2022-05-28 21:40 +0200
    Re: Firewall blocking my new Debian 11 server ports 80 and 443 Georgi Naplatanov <gosho@oles.biz> - 2022-05-28 21:50 +0200
    Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-28 22:00 +0200
    Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-28 23:10 +0200
      Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 00:30 +0200
        Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 17:00 +0200
          Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 17:00 +0200
            Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 17:30 +0200
              Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 17:40 +0200
                Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 18:30 +0200
                  Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 18:40 +0200
                  Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 18:40 +0200
                    Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 19:30 +0200
                      Re: Firewall blocking my new Debian 11 server ports 80 and 443 john doe <johndoe65534@mail.com> - 2022-05-29 20:30 +0200
                        Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 21:00 +0200
                        Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-29 21:30 +0200
                          Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 22:50 +0200
                            Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-29 23:00 +0200
                              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-30 00:30 +0200
                                Re: Firewall blocking my new Debian 11 server ports 80 and 443 john doe <johndoe65534@mail.com> - 2022-05-30 09:20 +0200
                                  Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-30 14:20 +0200
                                    Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-30 15:50 +0200
                                      Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-30 16:10 +0200
                                        Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-30 19:30 +0200
                                          Re: Firewall blocking my new Debian 11 server ports 80 and 443 Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2022-05-31 01:00 +0200
                                      Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-30 19:30 +0200
                                      Re: Firewall blocking my new Debian 11 server ports 80 and 443 Edwin Zimmerman <edwin@plainemail.net> - 2022-05-31 02:50 +0200
                                        Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-06-01 13:50 +0200
                                          Re: Firewall blocking my new Debian 11 server ports 80 and 443 john doe <johndoe65534@mail.com> - 2022-06-01 18:30 +0200
                                            Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-06-01 19:20 +0200
                              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Lee <ler762@gmail.com> - 2022-05-30 02:00 +0200
                                Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-30 02:20 +0200
                                  Re: Firewall blocking my new Debian 11 server ports 80 and 443 Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2022-05-30 02:40 +0200
                                Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-30 02:30 +0200
                              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Curt <curty@free.fr> - 2022-05-30 14:10 +0200
      Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 00:30 +0200
        Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 00:40 +0200
          Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 01:00 +0200
            Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 02:00 +0200
              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2022-05-29 02:20 +0200
                Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 02:40 +0200
              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Charles Kroeger <mbone@gmx.co.uk> - 2022-05-30 07:30 +0200
            Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-29 02:10 +0200
              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 02:20 +0200
            Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 03:10 +0200
              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 04:00 +0200
              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 12:50 +0200
                Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 13:30 +0200
                  Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 14:10 +0200
                    Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 14:30 +0200
                      Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 14:50 +0200
                  Re: Firewall blocking my new Debian 11 server ports 80 and 443 Erwan David <erwan@rail.eu.org> - 2022-05-29 16:00 +0200
                Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 14:10 +0200
                Re: Firewall blocking my new Debian 11 server ports 80 and 443 <tomas@tuxteam.de> - 2022-05-29 19:00 +0200
      Re: Firewall blocking my new Debian 11 server ports 80 and 443 Dan Ritter <dsr@randomstring.org> - 2022-05-29 00:30 +0200

Page 3 of 3 — ← Prev page 1 2 [3]


#248518

FromTimothy M Butterworth <timothy.m.butterworth@gmail.com>
Date2022-05-29 02:20 +0200
Message-ID<EseOZ-ZWP-1@gated-at.bofh.it>
In reply to#248515

[Multipart message — attachments visible in raw view] — view raw

On Sat, May 28, 2022 at 7:52 PM Tom Browder <tom.browder@gmail.com> wrote:

>
>
> On Sat, May 28, 2022 at 17:51 Tom Browder <tom.browder@gmail.com> wrote:
>
>> On Sat, May 28, 2022 at 17:30 IL Ka <kazakevichilya@gmail.com> wrote:
>>
>>> I am running an Apache server and using Qualys Lab’s server checker. It
>>>> shows no access to the server.
>>>>
>>>> Have you tried to telnet to port 80 from home? Do you see apache
>>> listening this port using ``ss``?
>>>
>>
>> On the new host I did:
>>
>>     $ sudo su
>>     # telnet 80
>>     Trying 0.0.0.80...
>>
>>
>> and gave up waiting.
>>
>
On the local host try running `telnet 127.0.0.1 80` If you can not connect
to the web server on the local host then it is likely not running. Try
running `sudo service --status-all` `sudo systemctl enable apache2` and
`sudo service apache2 start`




> Maybe I should remove all firewall progs and start from zero.
>
>

[toc] | [prev] | [next] | [standalone]


#248519

FromTom Browder <tom.browder@gmail.com>
Date2022-05-29 02:40 +0200
Message-ID<Esf8l-102q-3@gated-at.bofh.it>
In reply to#248518

[Multipart message — attachments visible in raw view] — view raw

On Sat, May 28, 2022 at 19:10 Timothy M Butterworth <
timothy.m.butterworth@gmail.com> wrote:
…

On the local host try running `telnet 127.0.0.1 80`
>

I was able to connect, thanks, Timothy!

Now what? I would really like to use ufw.

-Tom

[toc] | [prev] | [next] | [standalone]


#248563

FromCharles Kroeger <mbone@gmx.co.uk>
Date2022-05-30 07:30 +0200
Message-ID<EsG8x-1gz2-3@gated-at.bofh.it>
In reply to#248515
> Maybe I should remove all firewall progs and start from zero.

I would suggest you install Shorewall. it is not the pain in the arse that's
been the theme of this thread so far.

[toc] | [prev] | [next] | [standalone]


#248516

FromGreg Wooledge <greg@wooledge.org>
Date2022-05-29 02:10 +0200
Message-ID<EseFj-ZTN-1@gated-at.bofh.it>
In reply to#248514
On Sat, May 28, 2022 at 05:51:38PM -0500, Tom Browder wrote:
>     $ sudo su
>     # telnet 80
>     Trying 0.0.0.80...

... wow.  Just wow.  How can such a short excerpt contain so many failures?

1) "sudo su" is stupid.  You don't need TWO setuid programs to get a root
   shell.  Either use "sudo -s" or "su".  Hell, even "sudo bash" would
   make more sense and would be less wasteful.

2) As you can PLAINLY SEE in the output of telnet, you messed up the
   arguments.  You supplied "80" as a hostname/address, instead of a
   port number.  If you wanted to probe port 80 of your web server, you
   need to supply the web server's hostname/address as the first argument,
   and 80 (the port number) as the second argument.

3) You don't need to be root to telnet to another host (or the same host,
   if you're giving "localhost" as the hostname) in the first place.

[toc] | [prev] | [next] | [standalone]


#248517

FromTom Browder <tom.browder@gmail.com>
Date2022-05-29 02:20 +0200
Message-ID<EseOZ-ZWP-3@gated-at.bofh.it>
In reply to#248516

[Multipart message — attachments visible in raw view] — view raw

On Sat, May 28, 2022 at 19:01 Greg Wooledge <greg@wooledge.org> wrote:

> On Sat, May 28, 2022 at 05:51:38PM -0500, Tom Browder wrote:
> …
>
> ... wow.  Just wow.  How can such a short excerpt contain so many failures?


Greg, calm down.  I get it, but I haven’t unlearned years of muscle
memory—sorry.

And the telnet thing was something I haven’t done for MANY years and it was
a “shot in the dark—again, forgive me.

[toc] | [prev] | [next] | [standalone]


#248520

FromIL Ka <kazakevichilya@gmail.com>
Date2022-05-29 03:10 +0200
Message-ID<EsfBn-10qB-1@gated-at.bofh.it>
In reply to#248514

[Multipart message — attachments visible in raw view] — view raw

>
>
>     $ sudo su
>     # telnet 80
>     Trying 0.0.0.80...
>

1. You are using telnet wrong: it should be "telnet [host] [port]". Please
read "man telnet".
2. You do not need sudo to use telnet, do not do that
3. You should also check that Apache is running and listening to this port,
use ``ss -lt``.
For this command you _may_ use sudo to get process names (``sudo ss
-ltp``). Read ``ss --help``

If you were able to connect on this host, then try to connect to this
machine from outside using public IP

[toc] | [prev] | [next] | [standalone]


#248521

FromTom Browder <tom.browder@gmail.com>
Date2022-05-29 04:00 +0200
Message-ID<EsgnL-10F0-1@gated-at.bofh.it>
In reply to#248520

[Multipart message — attachments visible in raw view] — view raw

On Sat, May 28, 2022 at 20:06 IL Ka <kazakevichilya@gmail.com> wrote:

>
>>     $ sudo su
>>     # telnet 80
>>     Trying 0.0.0.80...
>>
>
> 1. You are using telnet wrong: it should be "telnet [host] [port]". Please
> read "man telnet".
> 2. You do not need sudo to use telnet, do not do that
> 3. You should also check that Apache is running and listening to this
> port, use ``ss -lt``.
> For this command you _may_ use sudo to get process names (``sudo ss
> -ltp``). Read ``ss --help``
>
> If you were able to connect on this host, then try to connect to this
> machine from outside using public IP
>

Thanks, I will try that tomorrow.

-Tom

[toc] | [prev] | [next] | [standalone]


#248522

FromTom Browder <tom.browder@gmail.com>
Date2022-05-29 12:50 +0200
Message-ID<EsoEF-15EC-15@gated-at.bofh.it>
In reply to#248520

[Multipart message — attachments visible in raw view] — view raw

On Sat, May 28, 2022 at 20:06 IL Ka <kazakevichilya@gmail.com> wrote:
...

3. You should also check that Apache is running and listening to this port,
> use ``ss -lt``.
> For this command you _may_ use sudo to get process names (``sudo ss
> -ltp``). Read ``ss --help``
>
> If you were able to connect on this host, then try to connect to this
> machine from outside using public IP
>

I can ssh in to the remote host. Then I tried telnet to port 80 on the same
host from the outside with the public IP and got no good response:

    $ telnet x.y.z.w 80
    Trying x.y.z.w...
    telnet: Unable to connect to remote host: No route to host

-Tom

[toc] | [prev] | [next] | [standalone]


#248523

FromTom Browder <tom.browder@gmail.com>
Date2022-05-29 13:30 +0200
Message-ID<Esphn-1660-5@gated-at.bofh.it>
In reply to#248522

[Multipart message — attachments visible in raw view] — view raw

On Sun, May 29, 2022 at 05:41 Tom Browder <tom.browder@gmail.com> wrote:

Does anyone have a good reason for me to NOT install and enable UFW?

-Tom

[toc] | [prev] | [next] | [standalone]


#248525

FromIL Ka <kazakevichilya@gmail.com>
Date2022-05-29 14:10 +0200
Message-ID<EspU5-16xg-9@gated-at.bofh.it>
In reply to#248523

[Multipart message — attachments visible in raw view] — view raw

>
>
>
> Does anyone have a good reason for me to NOT install and enable UFW?
>
>
ufw can't be used with ipset AFAIK, and I use ipset for many reasons
(fail2ban, block access outside of my country etc).
But If you only SSH your host from one static IP, you probably do not need
fail2ban at all.

Anyway, I am not sure that port 80 is blocked by your firewall and not your
hosting firewall

[toc] | [prev] | [next] | [standalone]


#248526

FromTom Browder <tom.browder@gmail.com>
Date2022-05-29 14:30 +0200
Message-ID<Esqdr-16FT-5@gated-at.bofh.it>
In reply to#248525

[Multipart message — attachments visible in raw view] — view raw

On Sun, May 29, 2022 at 07:06 IL Ka <kazakevichilya@gmail.com> wrote:

> Does anyone have a good reason for me to NOT install and enable UFW?
>>
>
> ufw can't be used with ipset AFAIK, and I use ipset for many reasons
> (fail2ban, block access outside of my country etc).
> But If you only SSH your host from one static IP, you probably do not need
> fail2ban at all.
>

Good to know. But does fail2ban require ipset?

Anyway, I am not sure that port 80 is blocked by your firewall and not your
> hosting firewall
>

They never have before in over 15 years, and, before I got this server
started, its mate was serving fine. But if the ufw doesn't work, I'll ask
them.

[toc] | [prev] | [next] | [standalone]


#248527

FromIL Ka <kazakevichilya@gmail.com>
Date2022-05-29 14:50 +0200
Message-ID<EsqwN-16SD-1@gated-at.bofh.it>
In reply to#248526

[Multipart message — attachments visible in raw view] — view raw

>
>
>
> Good to know. But does fail2ban require ipset?
>
No, but having several thousand rules is not convenient, so I prefer ipset


> They never have before in over 15 years, and, before I got this server
> started, its mate was serving fine. But if the ufw doesn't work, I'll ask
> them.
>

I'd start by switching to legacy iptables and running ``iptables -L -v
-n``.

[toc] | [prev] | [next] | [standalone]


#248530

FromErwan David <erwan@rail.eu.org>
Date2022-05-29 16:00 +0200
Message-ID<EsrCx-17tt-15@gated-at.bofh.it>
In reply to#248523
Le 29/05/2022 à 13:22, Tom Browder a écrit :
> On Sun, May 29, 2022 at 05:41 Tom Browder <tom.browder@gmail.com> wrote:
>
> Does anyone have a good reason for me to NOT install and enable UFW?
>
> -Tom

  good reason would be that thtere is obviously already something on 
your server magaing the firewalling. Having 2 different systems will 
lead to inconsistency and erratic behiaviour. First thing is to identify 
what is putting the rules you showed us. (rules that do not block ports 
80 and 443)

[toc] | [prev] | [next] | [standalone]


#248524

FromIL Ka <kazakevichilya@gmail.com>
Date2022-05-29 14:10 +0200
Message-ID<EspU5-16xg-13@gated-at.bofh.it>
In reply to#248522

[Multipart message — attachments visible in raw view] — view raw

>
>     $ telnet x.y.z.w 80
>     Trying x.y.z.w...
>     telnet: Unable to connect to remote host: No route to host
>
But you can ssh to this host, right?

Well, that means the firewall blocks your request and sends the ICMP
message "no route to host".

Switch to the legacy iptables using ``update-alternatives`` and check
``iptables -L -v -n`` again.
If no rule blocks this port, ask your hosting company.



>
>
>
>

[toc] | [prev] | [next] | [standalone]


#248540

From<tomas@tuxteam.de>
Date2022-05-29 19:00 +0200
Message-ID<EsuqK-19gd-7@gated-at.bofh.it>
In reply to#248522

[Multipart message — attachments visible in raw view] — view raw

On Sun, May 29, 2022 at 05:41:59AM -0500, Tom Browder wrote:
> On Sat, May 28, 2022 at 20:06 IL Ka <kazakevichilya@gmail.com> wrote:
> ...
> 
> 3. You should also check that Apache is running and listening to this port,
> > use ``ss -lt``.
> > For this command you _may_ use sudo to get process names (``sudo ss
> > -ltp``). Read ``ss --help``
> >
> > If you were able to connect on this host, then try to connect to this
> > machine from outside using public IP
> >
> 
> I can ssh in to the remote host. Then I tried telnet to port 80 on the same
> host from the outside with the public IP and got no good response:
> 
>     $ telnet x.y.z.w 80
>     Trying x.y.z.w...
>     telnet: Unable to connect to remote host: No route to host

I may be off, but I think a firewall shouldn't do that [1]. It can
lead to a "connection refused", which amounts to replying with a RST,
which corresponds to the REJECT treatment, and it can just not answer,
which leads to a timeout, corresponding to DROP.

What you are seeing is some router in the middle telling you it
doesn't know which way this x.y.z.w is (with an ICMP "Destination
unreachable"). Of course this can happen at your workstation, but
then it'd be quite probable you can't access x.y.z.w with ssh
either.

Firewalls can be configured to lie [2] in this way, alas. It very
much looks like your provider has a firewall between your rental
host and the rest of the world.

But take all that with a grain of salt or two.
Cheers

[1] and I believe your Linux firewall won't do that by default.
   You'd have to tell it so.
[2] Now destination port unreachable would be less of a lie,
   no?
-- 
t

[toc] | [prev] | [next] | [standalone]


#248512

FromDan Ritter <dsr@randomstring.org>
Date2022-05-29 00:30 +0200
Message-ID<Esd6x-YVu-7@gated-at.bofh.it>
In reply to#248507
Tom Browder wrote: 
> On Sat, May 28, 2022 at 14:11 Tom Browder <tom.browder@gmail.com> wrote:
> 
> > As the bare-iron server came from my long-time cloud provider (since
> > Debian 6), incoming ports 80 and 443 are blocked.
> 
> 
> A little more digging shows the new server is using fail2ban and nft
> tables, so I
> need help on how to properly allow https and http inbound.

We have established that you do not have a firewall on your
machine blocking ports. iptables and nftables control the same
underlying mechanism, and you have clearly set the policy to
ACCEPT.

Therefore, something outside of your machine is blocking the
ports, or you are misreading or misusing the tools that are
telling you the ports are blocked.

Tell us how you are checking the ports.

-dsr-

[toc] | [prev] | [standalone]


Page 3 of 3 — ← Prev page 1 2 [3]

Back to top | Article view | linux.debian.user


csiph-web