Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #248501 > unrolled thread
| Started by | Tom Browder <tom.browder@gmail.com> |
|---|---|
| First post | 2022-05-28 21:20 +0200 |
| Last post | 2022-05-29 00:30 +0200 |
| Articles | 16 on this page of 56 — 13 participants |
Back to article view | Back to linux.debian.user
Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-28 21:20 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Dan Ritter <dsr@randomstring.org> - 2022-05-28 21:40 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Georgi Naplatanov <gosho@oles.biz> - 2022-05-28 21:50 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-28 22:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-28 23:10 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 00:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 17:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 17:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 17:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 17:40 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 18:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 18:40 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 18:40 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 19:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 john doe <johndoe65534@mail.com> - 2022-05-29 20:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 21:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-29 21:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 22:50 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-29 23:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-30 00:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 john doe <johndoe65534@mail.com> - 2022-05-30 09:20 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-30 14:20 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-30 15:50 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-30 16:10 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-30 19:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2022-05-31 01:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-30 19:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Edwin Zimmerman <edwin@plainemail.net> - 2022-05-31 02:50 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-06-01 13:50 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 john doe <johndoe65534@mail.com> - 2022-06-01 18:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-06-01 19:20 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Lee <ler762@gmail.com> - 2022-05-30 02:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-30 02:20 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2022-05-30 02:40 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-30 02:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Curt <curty@free.fr> - 2022-05-30 14:10 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 00:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 00:40 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 01:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 02:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2022-05-29 02:20 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 02:40 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Charles Kroeger <mbone@gmx.co.uk> - 2022-05-30 07:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-29 02:10 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 02:20 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 03:10 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 04:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 12:50 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 13:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 14:10 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 14:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 14:50 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Erwan David <erwan@rail.eu.org> - 2022-05-29 16:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 14:10 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 <tomas@tuxteam.de> - 2022-05-29 19:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Dan Ritter <dsr@randomstring.org> - 2022-05-29 00:30 +0200
Page 3 of 3 — ← Prev page 1 2 [3]
| From | Timothy M Butterworth <timothy.m.butterworth@gmail.com> |
|---|---|
| Date | 2022-05-29 02:20 +0200 |
| Message-ID | <EseOZ-ZWP-1@gated-at.bofh.it> |
| In reply to | #248515 |
[Multipart message — attachments visible in raw view] — view raw
On Sat, May 28, 2022 at 7:52 PM Tom Browder <tom.browder@gmail.com> wrote: > > > On Sat, May 28, 2022 at 17:51 Tom Browder <tom.browder@gmail.com> wrote: > >> On Sat, May 28, 2022 at 17:30 IL Ka <kazakevichilya@gmail.com> wrote: >> >>> I am running an Apache server and using Qualys Lab’s server checker. It >>>> shows no access to the server. >>>> >>>> Have you tried to telnet to port 80 from home? Do you see apache >>> listening this port using ``ss``? >>> >> >> On the new host I did: >> >> $ sudo su >> # telnet 80 >> Trying 0.0.0.80... >> >> >> and gave up waiting. >> > On the local host try running `telnet 127.0.0.1 80` If you can not connect to the web server on the local host then it is likely not running. Try running `sudo service --status-all` `sudo systemctl enable apache2` and `sudo service apache2 start` > Maybe I should remove all firewall progs and start from zero. > >
[toc] | [prev] | [next] | [standalone]
| From | Tom Browder <tom.browder@gmail.com> |
|---|---|
| Date | 2022-05-29 02:40 +0200 |
| Message-ID | <Esf8l-102q-3@gated-at.bofh.it> |
| In reply to | #248518 |
[Multipart message — attachments visible in raw view] — view raw
On Sat, May 28, 2022 at 19:10 Timothy M Butterworth < timothy.m.butterworth@gmail.com> wrote: … On the local host try running `telnet 127.0.0.1 80` > I was able to connect, thanks, Timothy! Now what? I would really like to use ufw. -Tom
[toc] | [prev] | [next] | [standalone]
| From | Charles Kroeger <mbone@gmx.co.uk> |
|---|---|
| Date | 2022-05-30 07:30 +0200 |
| Message-ID | <EsG8x-1gz2-3@gated-at.bofh.it> |
| In reply to | #248515 |
> Maybe I should remove all firewall progs and start from zero. I would suggest you install Shorewall. it is not the pain in the arse that's been the theme of this thread so far.
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <greg@wooledge.org> |
|---|---|
| Date | 2022-05-29 02:10 +0200 |
| Message-ID | <EseFj-ZTN-1@gated-at.bofh.it> |
| In reply to | #248514 |
On Sat, May 28, 2022 at 05:51:38PM -0500, Tom Browder wrote: > $ sudo su > # telnet 80 > Trying 0.0.0.80... ... wow. Just wow. How can such a short excerpt contain so many failures? 1) "sudo su" is stupid. You don't need TWO setuid programs to get a root shell. Either use "sudo -s" or "su". Hell, even "sudo bash" would make more sense and would be less wasteful. 2) As you can PLAINLY SEE in the output of telnet, you messed up the arguments. You supplied "80" as a hostname/address, instead of a port number. If you wanted to probe port 80 of your web server, you need to supply the web server's hostname/address as the first argument, and 80 (the port number) as the second argument. 3) You don't need to be root to telnet to another host (or the same host, if you're giving "localhost" as the hostname) in the first place.
[toc] | [prev] | [next] | [standalone]
| From | Tom Browder <tom.browder@gmail.com> |
|---|---|
| Date | 2022-05-29 02:20 +0200 |
| Message-ID | <EseOZ-ZWP-3@gated-at.bofh.it> |
| In reply to | #248516 |
[Multipart message — attachments visible in raw view] — view raw
On Sat, May 28, 2022 at 19:01 Greg Wooledge <greg@wooledge.org> wrote: > On Sat, May 28, 2022 at 05:51:38PM -0500, Tom Browder wrote: > … > > ... wow. Just wow. How can such a short excerpt contain so many failures? Greg, calm down. I get it, but I haven’t unlearned years of muscle memory—sorry. And the telnet thing was something I haven’t done for MANY years and it was a “shot in the dark—again, forgive me.
[toc] | [prev] | [next] | [standalone]
| From | IL Ka <kazakevichilya@gmail.com> |
|---|---|
| Date | 2022-05-29 03:10 +0200 |
| Message-ID | <EsfBn-10qB-1@gated-at.bofh.it> |
| In reply to | #248514 |
[Multipart message — attachments visible in raw view] — view raw
> > > $ sudo su > # telnet 80 > Trying 0.0.0.80... > 1. You are using telnet wrong: it should be "telnet [host] [port]". Please read "man telnet". 2. You do not need sudo to use telnet, do not do that 3. You should also check that Apache is running and listening to this port, use ``ss -lt``. For this command you _may_ use sudo to get process names (``sudo ss -ltp``). Read ``ss --help`` If you were able to connect on this host, then try to connect to this machine from outside using public IP
[toc] | [prev] | [next] | [standalone]
| From | Tom Browder <tom.browder@gmail.com> |
|---|---|
| Date | 2022-05-29 04:00 +0200 |
| Message-ID | <EsgnL-10F0-1@gated-at.bofh.it> |
| In reply to | #248520 |
[Multipart message — attachments visible in raw view] — view raw
On Sat, May 28, 2022 at 20:06 IL Ka <kazakevichilya@gmail.com> wrote: > >> $ sudo su >> # telnet 80 >> Trying 0.0.0.80... >> > > 1. You are using telnet wrong: it should be "telnet [host] [port]". Please > read "man telnet". > 2. You do not need sudo to use telnet, do not do that > 3. You should also check that Apache is running and listening to this > port, use ``ss -lt``. > For this command you _may_ use sudo to get process names (``sudo ss > -ltp``). Read ``ss --help`` > > If you were able to connect on this host, then try to connect to this > machine from outside using public IP > Thanks, I will try that tomorrow. -Tom
[toc] | [prev] | [next] | [standalone]
| From | Tom Browder <tom.browder@gmail.com> |
|---|---|
| Date | 2022-05-29 12:50 +0200 |
| Message-ID | <EsoEF-15EC-15@gated-at.bofh.it> |
| In reply to | #248520 |
[Multipart message — attachments visible in raw view] — view raw
On Sat, May 28, 2022 at 20:06 IL Ka <kazakevichilya@gmail.com> wrote:
...
3. You should also check that Apache is running and listening to this port,
> use ``ss -lt``.
> For this command you _may_ use sudo to get process names (``sudo ss
> -ltp``). Read ``ss --help``
>
> If you were able to connect on this host, then try to connect to this
> machine from outside using public IP
>
I can ssh in to the remote host. Then I tried telnet to port 80 on the same
host from the outside with the public IP and got no good response:
$ telnet x.y.z.w 80
Trying x.y.z.w...
telnet: Unable to connect to remote host: No route to host
-Tom
[toc] | [prev] | [next] | [standalone]
| From | Tom Browder <tom.browder@gmail.com> |
|---|---|
| Date | 2022-05-29 13:30 +0200 |
| Message-ID | <Esphn-1660-5@gated-at.bofh.it> |
| In reply to | #248522 |
[Multipart message — attachments visible in raw view] — view raw
On Sun, May 29, 2022 at 05:41 Tom Browder <tom.browder@gmail.com> wrote: Does anyone have a good reason for me to NOT install and enable UFW? -Tom
[toc] | [prev] | [next] | [standalone]
| From | IL Ka <kazakevichilya@gmail.com> |
|---|---|
| Date | 2022-05-29 14:10 +0200 |
| Message-ID | <EspU5-16xg-9@gated-at.bofh.it> |
| In reply to | #248523 |
[Multipart message — attachments visible in raw view] — view raw
> > > > Does anyone have a good reason for me to NOT install and enable UFW? > > ufw can't be used with ipset AFAIK, and I use ipset for many reasons (fail2ban, block access outside of my country etc). But If you only SSH your host from one static IP, you probably do not need fail2ban at all. Anyway, I am not sure that port 80 is blocked by your firewall and not your hosting firewall
[toc] | [prev] | [next] | [standalone]
| From | Tom Browder <tom.browder@gmail.com> |
|---|---|
| Date | 2022-05-29 14:30 +0200 |
| Message-ID | <Esqdr-16FT-5@gated-at.bofh.it> |
| In reply to | #248525 |
[Multipart message — attachments visible in raw view] — view raw
On Sun, May 29, 2022 at 07:06 IL Ka <kazakevichilya@gmail.com> wrote: > Does anyone have a good reason for me to NOT install and enable UFW? >> > > ufw can't be used with ipset AFAIK, and I use ipset for many reasons > (fail2ban, block access outside of my country etc). > But If you only SSH your host from one static IP, you probably do not need > fail2ban at all. > Good to know. But does fail2ban require ipset? Anyway, I am not sure that port 80 is blocked by your firewall and not your > hosting firewall > They never have before in over 15 years, and, before I got this server started, its mate was serving fine. But if the ufw doesn't work, I'll ask them.
[toc] | [prev] | [next] | [standalone]
| From | IL Ka <kazakevichilya@gmail.com> |
|---|---|
| Date | 2022-05-29 14:50 +0200 |
| Message-ID | <EsqwN-16SD-1@gated-at.bofh.it> |
| In reply to | #248526 |
[Multipart message — attachments visible in raw view] — view raw
> > > > Good to know. But does fail2ban require ipset? > No, but having several thousand rules is not convenient, so I prefer ipset > They never have before in over 15 years, and, before I got this server > started, its mate was serving fine. But if the ufw doesn't work, I'll ask > them. > I'd start by switching to legacy iptables and running ``iptables -L -v -n``.
[toc] | [prev] | [next] | [standalone]
| From | Erwan David <erwan@rail.eu.org> |
|---|---|
| Date | 2022-05-29 16:00 +0200 |
| Message-ID | <EsrCx-17tt-15@gated-at.bofh.it> |
| In reply to | #248523 |
Le 29/05/2022 à 13:22, Tom Browder a écrit : > On Sun, May 29, 2022 at 05:41 Tom Browder <tom.browder@gmail.com> wrote: > > Does anyone have a good reason for me to NOT install and enable UFW? > > -Tom good reason would be that thtere is obviously already something on your server magaing the firewalling. Having 2 different systems will lead to inconsistency and erratic behiaviour. First thing is to identify what is putting the rules you showed us. (rules that do not block ports 80 and 443)
[toc] | [prev] | [next] | [standalone]
| From | IL Ka <kazakevichilya@gmail.com> |
|---|---|
| Date | 2022-05-29 14:10 +0200 |
| Message-ID | <EspU5-16xg-13@gated-at.bofh.it> |
| In reply to | #248522 |
[Multipart message — attachments visible in raw view] — view raw
> > $ telnet x.y.z.w 80 > Trying x.y.z.w... > telnet: Unable to connect to remote host: No route to host > But you can ssh to this host, right? Well, that means the firewall blocks your request and sends the ICMP message "no route to host". Switch to the legacy iptables using ``update-alternatives`` and check ``iptables -L -v -n`` again. If no rule blocks this port, ask your hosting company. > > > >
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2022-05-29 19:00 +0200 |
| Message-ID | <EsuqK-19gd-7@gated-at.bofh.it> |
| In reply to | #248522 |
[Multipart message — attachments visible in raw view] — view raw
On Sun, May 29, 2022 at 05:41:59AM -0500, Tom Browder wrote: > On Sat, May 28, 2022 at 20:06 IL Ka <kazakevichilya@gmail.com> wrote: > ... > > 3. You should also check that Apache is running and listening to this port, > > use ``ss -lt``. > > For this command you _may_ use sudo to get process names (``sudo ss > > -ltp``). Read ``ss --help`` > > > > If you were able to connect on this host, then try to connect to this > > machine from outside using public IP > > > > I can ssh in to the remote host. Then I tried telnet to port 80 on the same > host from the outside with the public IP and got no good response: > > $ telnet x.y.z.w 80 > Trying x.y.z.w... > telnet: Unable to connect to remote host: No route to host I may be off, but I think a firewall shouldn't do that [1]. It can lead to a "connection refused", which amounts to replying with a RST, which corresponds to the REJECT treatment, and it can just not answer, which leads to a timeout, corresponding to DROP. What you are seeing is some router in the middle telling you it doesn't know which way this x.y.z.w is (with an ICMP "Destination unreachable"). Of course this can happen at your workstation, but then it'd be quite probable you can't access x.y.z.w with ssh either. Firewalls can be configured to lie [2] in this way, alas. It very much looks like your provider has a firewall between your rental host and the rest of the world. But take all that with a grain of salt or two. Cheers [1] and I believe your Linux firewall won't do that by default. You'd have to tell it so. [2] Now destination port unreachable would be less of a lie, no? -- t
[toc] | [prev] | [next] | [standalone]
| From | Dan Ritter <dsr@randomstring.org> |
|---|---|
| Date | 2022-05-29 00:30 +0200 |
| Message-ID | <Esd6x-YVu-7@gated-at.bofh.it> |
| In reply to | #248507 |
Tom Browder wrote: > On Sat, May 28, 2022 at 14:11 Tom Browder <tom.browder@gmail.com> wrote: > > > As the bare-iron server came from my long-time cloud provider (since > > Debian 6), incoming ports 80 and 443 are blocked. > > > A little more digging shows the new server is using fail2ban and nft > tables, so I > need help on how to properly allow https and http inbound. We have established that you do not have a firewall on your machine blocking ports. iptables and nftables control the same underlying mechanism, and you have clearly set the policy to ACCEPT. Therefore, something outside of your machine is blocking the ports, or you are misreading or misusing the tools that are telling you the ports are blocked. Tell us how you are checking the ports. -dsr-
[toc] | [prev] | [standalone]
Page 3 of 3 — ← Prev page 1 2 [3]
Back to top | Article view | linux.debian.user
csiph-web