Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #248501 > unrolled thread

Firewall blocking my new Debian 11 server ports 80 and 443

Started byTom Browder <tom.browder@gmail.com>
First post2022-05-28 21:20 +0200
Last post2022-05-29 00:30 +0200
Articles 20 on this page of 56 — 13 participants

Back to article view | Back to linux.debian.user


Contents

  Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-28 21:20 +0200
    Re: Firewall blocking my new Debian 11 server ports 80 and 443 Dan Ritter <dsr@randomstring.org> - 2022-05-28 21:40 +0200
    Re: Firewall blocking my new Debian 11 server ports 80 and 443 Georgi Naplatanov <gosho@oles.biz> - 2022-05-28 21:50 +0200
    Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-28 22:00 +0200
    Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-28 23:10 +0200
      Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 00:30 +0200
        Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 17:00 +0200
          Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 17:00 +0200
            Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 17:30 +0200
              Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 17:40 +0200
                Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 18:30 +0200
                  Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 18:40 +0200
                  Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 18:40 +0200
                    Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 19:30 +0200
                      Re: Firewall blocking my new Debian 11 server ports 80 and 443 john doe <johndoe65534@mail.com> - 2022-05-29 20:30 +0200
                        Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 21:00 +0200
                        Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-29 21:30 +0200
                          Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 22:50 +0200
                            Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-29 23:00 +0200
                              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-30 00:30 +0200
                                Re: Firewall blocking my new Debian 11 server ports 80 and 443 john doe <johndoe65534@mail.com> - 2022-05-30 09:20 +0200
                                  Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-30 14:20 +0200
                                    Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-30 15:50 +0200
                                      Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-30 16:10 +0200
                                        Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-30 19:30 +0200
                                          Re: Firewall blocking my new Debian 11 server ports 80 and 443 Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2022-05-31 01:00 +0200
                                      Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-30 19:30 +0200
                                      Re: Firewall blocking my new Debian 11 server ports 80 and 443 Edwin Zimmerman <edwin@plainemail.net> - 2022-05-31 02:50 +0200
                                        Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-06-01 13:50 +0200
                                          Re: Firewall blocking my new Debian 11 server ports 80 and 443 john doe <johndoe65534@mail.com> - 2022-06-01 18:30 +0200
                                            Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-06-01 19:20 +0200
                              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Lee <ler762@gmail.com> - 2022-05-30 02:00 +0200
                                Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-30 02:20 +0200
                                  Re: Firewall blocking my new Debian 11 server ports 80 and 443 Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2022-05-30 02:40 +0200
                                Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-30 02:30 +0200
                              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Curt <curty@free.fr> - 2022-05-30 14:10 +0200
      Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 00:30 +0200
        Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 00:40 +0200
          Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 01:00 +0200
            Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 02:00 +0200
              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2022-05-29 02:20 +0200
                Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 02:40 +0200
              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Charles Kroeger <mbone@gmx.co.uk> - 2022-05-30 07:30 +0200
            Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-29 02:10 +0200
              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 02:20 +0200
            Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 03:10 +0200
              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 04:00 +0200
              Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 12:50 +0200
                Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 13:30 +0200
                  Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 14:10 +0200
                    Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 14:30 +0200
                      Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 14:50 +0200
                  Re: Firewall blocking my new Debian 11 server ports 80 and 443 Erwan David <erwan@rail.eu.org> - 2022-05-29 16:00 +0200
                Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 14:10 +0200
                Re: Firewall blocking my new Debian 11 server ports 80 and 443 <tomas@tuxteam.de> - 2022-05-29 19:00 +0200
      Re: Firewall blocking my new Debian 11 server ports 80 and 443 Dan Ritter <dsr@randomstring.org> - 2022-05-29 00:30 +0200

Page 1 of 3  [1] 2 3  Next page →


#248501 — Firewall blocking my new Debian 11 server ports 80 and 443

FromTom Browder <tom.browder@gmail.com>
Date2022-05-28 21:20 +0200
SubjectFirewall blocking my new Debian 11 server ports 80 and 443
Message-ID<Esa8G-XdI-19@gated-at.bofh.it>
As the bare-iron server came from my long-time cloud provider (since
Debian 6), incoming ports 80 and 443 are blocked.

I ran my usual iptables command for new servers from them, but this
time the default settings were different so it didn't work.

Output from "sudo iptables -S" before my attempt:

-P INPUT ACCEPT
-P FORWARD ACCEPT
-P OUTPUT ACCEPT
-N f2b-sshd
-A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd
-A f2b-sshd -s 62.204.41.56/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 61.177.173.48/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 167.172.187.120/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 43.156.124.69/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 43.154.46.209/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 61.177.172.98/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 122.160.233.137/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -j RETURN

My usual incantation and response:

    # sudo iptables -A IN_public_allow -p tcp -m tcp --dport  80 -m
conntrack --ctstate NEW,UNTRACKED -j ACCEPT
    iptables: No chain/target/match by that name.

Then I tried:

    # sudo iptables -A  INPUT -p tcp -m tcp --dport  80 -m conntrack
--ctstate NEW,UNTRACKED -j ACCEPT
    # sudo iptables -A  INPUT -p tcp -m tcp --dport  443 -m conntrack
--ctstate NEW,UNTRACKED -j ACCEPT

Again checking status:

# sudo iptables -S
-P INPUT ACCEPT
-P FORWARD ACCEPT
-P OUTPUT ACCEPT
-N f2b-sshd
-A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd
-A INPUT -p tcp -m tcp --dport 80 -m conntrack --ctstate NEW,UNTRACKED -j ACCEPT
-A INPUT -p tcp -m tcp --dport 443 -m conntrack --ctstate
NEW,UNTRACKED -j ACCEPT
-A INPUT -p tcp -m tcp --dport 80 -m conntrack --ctstate NEW,UNTRACKED -j ACCEPT
-A f2b-sshd -s 62.204.41.56/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 61.177.173.48/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 167.172.187.120/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 43.156.124.69/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 43.154.46.209/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 61.177.172.98/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 122.160.233.137/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -j RETURN

But no open ports in spite of the output shown.

I am considering moving to ufw but am reluctant due to the possibility
of getting locked-out of my remote server. I am used to logging in
with two separate terminals to avoid that during initial setup but
want to make sure that is safe.

Suggestions welcome!

-Tom

[toc] | [next] | [standalone]


#248502

FromDan Ritter <dsr@randomstring.org>
Date2022-05-28 21:40 +0200
Message-ID<Esas1-XjK-3@gated-at.bofh.it>
In reply to#248501
Tom Browder wrote: 
> As the bare-iron server came from my long-time cloud provider (since
> Debian 6), incoming ports 80 and 443 are blocked.
> 
> I ran my usual iptables command for new servers from them, but this
> time the default settings were different so it didn't work.
> 
> Output from "sudo iptables -S" before my attempt:
> 
> -P INPUT ACCEPT
> -P FORWARD ACCEPT
> -P OUTPUT ACCEPT
> -N f2b-sshd
> -A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd
> -A f2b-sshd -s 62.204.41.56/32 -j REJECT --reject-with icmp-port-unreachable
> -A f2b-sshd -s 61.177.173.48/32 -j REJECT --reject-with icmp-port-unreachable
> -A f2b-sshd -s 167.172.187.120/32 -j REJECT --reject-with icmp-port-unreachable
> -A f2b-sshd -s 43.156.124.69/32 -j REJECT --reject-with icmp-port-unreachable
> -A f2b-sshd -s 43.154.46.209/32 -j REJECT --reject-with icmp-port-unreachable
> -A f2b-sshd -s 61.177.172.98/32 -j REJECT --reject-with icmp-port-unreachable
> -A f2b-sshd -s 122.160.233.137/32 -j REJECT --reject-with icmp-port-unreachable
> -A f2b-sshd -j RETURN

This is strongly suggestive of having fail2ban installed.

The -P statements set default policy for each of the default
chains: if nothing else happens to a packet, that's the policy.

> My usual incantation and response:
> 
>     # sudo iptables -A IN_public_allow -p tcp -m tcp --dport  80 -m
> conntrack --ctstate NEW,UNTRACKED -j ACCEPT
>     iptables: No chain/target/match by that name.

IN_public_allow hasn't been created and isn't a default.

> Then I tried:
> 
>     # sudo iptables -A  INPUT -p tcp -m tcp --dport  80 -m conntrack
> --ctstate NEW,UNTRACKED -j ACCEPT
>     # sudo iptables -A  INPUT -p tcp -m tcp --dport  443 -m conntrack
> --ctstate NEW,UNTRACKED -j ACCEPT

Which is fine, but remember that the default policies all the
way around are ACCEPT, so this doesn't change anything until you
change the policy.

> Again checking status:

[normal output]


> But no open ports in spite of the output shown.

1. How are you checking that?

2. Have you asked the cloud provider if they need an extra step
on their end to open up the ports? It's likely on their side.

> I am considering moving to ufw but am reluctant due to the possibility
> of getting locked-out of my remote server. I am used to logging in
> with two separate terminals to avoid that during initial setup but
> want to make sure that is safe.

The cloud provider should provide console access via emulated
serial port or similar for you to get in without going through
the VM's network.

-dsr-

[toc] | [prev] | [next] | [standalone]


#248503

FromGeorgi Naplatanov <gosho@oles.biz>
Date2022-05-28 21:50 +0200
Message-ID<EsaBH-Xnw-29@gated-at.bofh.it>
In reply to#248501
On 5/28/22 22:11, Tom Browder wrote:
> As the bare-iron server came from my long-time cloud provider (since
> Debian 6), incoming ports 80 and 443 are blocked.
> 
> I ran my usual iptables command for new servers from them, but this
> time the default settings were different so it didn't work.

Try to flush the tables and (re)set default policies for the existing
chains.

> Output from "sudo iptables -S" before my attempt:
> 
> -P INPUT ACCEPT
> -P FORWARD ACCEPT
> -P OUTPUT ACCEPT
> -N f2b-sshd
> -A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd
> -A f2b-sshd -s 62.204.41.56/32 -j REJECT --reject-with icmp-port-unreachable
> -A f2b-sshd -s 61.177.173.48/32 -j REJECT --reject-with icmp-port-unreachable
> -A f2b-sshd -s 167.172.187.120/32 -j REJECT --reject-with icmp-port-unreachable
> -A f2b-sshd -s 43.156.124.69/32 -j REJECT --reject-with icmp-port-unreachable
> -A f2b-sshd -s 43.154.46.209/32 -j REJECT --reject-with icmp-port-unreachable
> -A f2b-sshd -s 61.177.172.98/32 -j REJECT --reject-with icmp-port-unreachable
> -A f2b-sshd -s 122.160.233.137/32 -j REJECT --reject-with icmp-port-unreachable
> -A f2b-sshd -j RETURN
> 
> My usual incantation and response:
> 
>     # sudo iptables -A IN_public_allow -p tcp -m tcp --dport  80 -m
> conntrack --ctstate NEW,UNTRACKED -j ACCEPT
>     iptables: No chain/target/match by that name.

You have no chain "IN_public_allow". Probably you should create it.


> Then I tried:
> 
>     # sudo iptables -A  INPUT -p tcp -m tcp --dport  80 -m conntrack
> --ctstate NEW,UNTRACKED -j ACCEPT
>     # sudo iptables -A  INPUT -p tcp -m tcp --dport  443 -m conntrack
> --ctstate NEW,UNTRACKED -j ACCEPT

It's a good practice to set input/output network interfaces.

> Again checking status:
> 
> # sudo iptables -S
> -P INPUT ACCEPT
> -P FORWARD ACCEPT
> -P OUTPUT ACCEPT
> -N f2b-sshd
> -A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd
> -A INPUT -p tcp -m tcp --dport 80 -m conntrack --ctstate NEW,UNTRACKED -j ACCEPT
> -A INPUT -p tcp -m tcp --dport 443 -m conntrack --ctstate
> NEW,UNTRACKED -j ACCEPT
> -A INPUT -p tcp -m tcp --dport 80 -m conntrack --ctstate NEW,UNTRACKED -j ACCEPT

You have second rule for port 80/tcp, do you need it?

> -A f2b-sshd -s 62.204.41.56/32 -j REJECT --reject-with icmp-port-unreachable
> -A f2b-sshd -s 61.177.173.48/32 -j REJECT --reject-with icmp-port-unreachable
> -A f2b-sshd -s 167.172.187.120/32 -j REJECT --reject-with icmp-port-unreachable
> -A f2b-sshd -s 43.156.124.69/32 -j REJECT --reject-with icmp-port-unreachable
> -A f2b-sshd -s 43.154.46.209/32 -j REJECT --reject-with icmp-port-unreachable
> -A f2b-sshd -s 61.177.172.98/32 -j REJECT --reject-with icmp-port-unreachable
> -A f2b-sshd -s 122.160.233.137/32 -j REJECT --reject-with icmp-port-unreachable
> -A f2b-sshd -j RETURN
> 
> But no open ports in spite of the output shown.
> 
> I am considering moving to ufw but am reluctant due to the possibility
> of getting locked-out of my remote server. I am used to logging in
> with two separate terminals to avoid that during initial setup but
> want to make sure that is safe.
> 

Kind regards
Georgi

[toc] | [prev] | [next] | [standalone]


#248504

FromIL Ka <kazakevichilya@gmail.com>
Date2022-05-28 22:00 +0200
Message-ID<EsaLn-XqP-9@gated-at.bofh.it>
In reply to#248501

[Multipart message — attachments visible in raw view] — view raw

>
>
>
> -P INPUT ACCEPT
> -P FORWARD ACCEPT
> -P OUTPUT ACCEPT
> -N f2b-sshd
> -A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd
> -A f2b-sshd -s 62.204.41.56/32 -j REJECT --reject-with
> icmp-port-unreachable
> -A f2b-sshd -s 61.177.173.48/32 -j REJECT --reject-with
> icmp-port-unreachable
> -A f2b-sshd -s 167.172.187.120/32 -j REJECT --reject-with
> icmp-port-unreachable
> -A f2b-sshd -s 43.156.124.69/32 -j REJECT --reject-with
> icmp-port-unreachable
> -A f2b-sshd -s 43.154.46.209/32 -j REJECT --reject-with
> icmp-port-unreachable
> -A f2b-sshd -s 61.177.172.98/32 -j REJECT --reject-with
> icmp-port-unreachable
> -A f2b-sshd -s 122.160.233.137/32 -j REJECT --reject-with
> icmp-port-unreachable
> -A f2b-sshd -j RETURN
>


This is fail2ban chain to block bots, but I strongly suggest to use ipset
and not to store each network as separate rule.

On my Debian server I use netfilter-persistent with ipset plugin and
fail2ban.
Works like charm!

https://dhtar.com/make-ipset-and-iptables-configurations-persistent-in-debianubuntu.html

<https://dhtar.com/make-ipset-and-iptables-configurations-persistent-in-debianubuntu.html>
But since policy is "ACCEPT", other ports are open.


> My usual incantation and response:
>
>     # sudo iptables -A IN_public_allow -p tcp -m tcp --dport  80 -m
> conntrack --ctstate NEW,UNTRACKED -j ACCEPT
>     iptables: No chain/target/match by that name.
>
>
What is "IN_public_allow"
I do not see chain with this name. Do you?




> # sudo iptables -S
> -P INPUT ACCEPT
> -P FORWARD ACCEPT
> -P OUTPUT ACCEPT
> -N f2b-sshd
> -A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd
> -A INPUT -p tcp -m tcp --dport 80 -m conntrack --ctstate NEW,UNTRACKED -j
> ACCEPT
> -A INPUT -p tcp -m tcp --dport 443 -m conntrack --ctstate
> ...
> But no open ports in spite of the output shown.
>

Hmm, I see 80 and 443 are open here. How did you check?
(I suggest to use multiple ports rule (multiport), btw)


> I am considering moving to ufw

It is up to you. I see no reason to use ufw. At least, it doesn't support
ipset:)

Also, check (using update-alternatives) if you are using iptables of nft


You may be interested in good iptables tutorial:
https://tldp.org/LDP/nag2/nag2.pdf
(section 9.8)

[toc] | [prev] | [next] | [standalone]


#248507

FromTom Browder <tom.browder@gmail.com>
Date2022-05-28 23:10 +0200
Message-ID<EsbR7-Yhw-7@gated-at.bofh.it>
In reply to#248501

[Multipart message — attachments visible in raw view] — view raw

On Sat, May 28, 2022 at 14:11 Tom Browder <tom.browder@gmail.com> wrote:

> As the bare-iron server came from my long-time cloud provider (since
> Debian 6), incoming ports 80 and 443 are blocked.


A little more digging shows the new server is using fail2ban and nft
tables, so I
need help on how to properly allow https and http inbound.

Thanks.

-Tom

[toc] | [prev] | [next] | [standalone]


#248510

FromIL Ka <kazakevichilya@gmail.com>
Date2022-05-29 00:30 +0200
Message-ID<Esd6x-YVu-1@gated-at.bofh.it>
In reply to#248507

[Multipart message — attachments visible in raw view] — view raw

>
>
>
> A little more digging shows the new server is using fail2ban and nft
> tables, so I
> need help on how to properly allow https and http inbound.
>
>
I am not familiar with nft, bit you can switch to iptables using
``update-alternatives``

# update-alternatives --set iptables /usr/sbin/iptables-legacy
# update-alternatives --set ip6tables /usr/sbin/ip6tables-legacy
# update-alternatives --set arptables /usr/sbin/arptables-legacy
# update-alternatives --set ebtables /usr/sbin/ebtables-legacy

I am using iptables on my servers. nfs is good, but I do not have time (for
now) to learn it

[toc] | [prev] | [next] | [standalone]


#248531

FromTom Browder <tom.browder@gmail.com>
Date2022-05-29 17:00 +0200
Message-ID<EssyB-183s-3@gated-at.bofh.it>
In reply to#248510

[Multipart message — attachments visible in raw view] — view raw

On Sat, May 28, 2022 at 17:24 IL Ka <kazakevichilya@gmail.com> wrote:

> ...

I am not familiar with nft, bit you can switch to iptables using
>> ``update-alternatives``
>>
>
> # update-alternatives --set iptables /usr/sbin/iptables-legacy
> # update-alternatives --set ip6tables /usr/sbin/ip6tables-legacy
> # update-alternatives --set arptables /usr/sbin/arptables-legacy
> # update-alternatives --set ebtables /usr/sbin/ebtables-legacy
>

Do I have to switch all four *legacy *tables?

-Tom

[toc] | [prev] | [next] | [standalone]


#248532

FromIL Ka <kazakevichilya@gmail.com>
Date2022-05-29 17:00 +0200
Message-ID<EssyB-183s-1@gated-at.bofh.it>
In reply to#248531

[Multipart message — attachments visible in raw view] — view raw

>
>
>> Do I have to switch all four *legacy *tables?
>

yes

[toc] | [prev] | [next] | [standalone]


#248534

FromTom Browder <tom.browder@gmail.com>
Date2022-05-29 17:30 +0200
Message-ID<Est1D-18rL-3@gated-at.bofh.it>
In reply to#248532

[Multipart message — attachments visible in raw view] — view raw

On Sun, May 29, 2022 at 09:51 IL Ka <kazakevichilya@gmail.com> wrote:

>
>>> Do I have to switch all four *legacy *tables?
>>
>
> yes
>

When running those, I'm told neither the arptablrs nor the ebtables are
registered (not installed). Should I install them?

>

[toc] | [prev] | [next] | [standalone]


#248535

FromIL Ka <kazakevichilya@gmail.com>
Date2022-05-29 17:40 +0200
Message-ID<Estbk-18uQ-9@gated-at.bofh.it>
In reply to#248534

[Multipart message — attachments visible in raw view] — view raw

> When running those, I'm told neither the arptablrs nor the ebtables are
> registered (not installed). Should I install them?
>
No.

So, you now have legacy (classic) iptables, right?
What is the output of ``iptables -L -v -n`` and ``iptables -S`` ?

[toc] | [prev] | [next] | [standalone]


#248536

FromTom Browder <tom.browder@gmail.com>
Date2022-05-29 18:30 +0200
Message-ID<EstXH-196K-1@gated-at.bofh.it>
In reply to#248535
On Sun, May 29, 2022 at 10:33 AM IL Ka <kazakevichilya@gmail.com> wrote:
>
>
>> When running those, I'm told neither the arptablrs nor the ebtables are registered (not installed). Should I install them?
>
> No.
>
> So, you now have legacy (classic) iptables, right?

Yes.

> What is the output of ``iptables -L -v -n``

Chain INPUT (policy ACCEPT 279 packets, 36670 bytes)
 pkts bytes target     prot opt in     out     source
destination
 1387  150K f2b-sshd   tcp  --  *      *       0.0.0.0/0
0.0.0.0/0            multiport dports 22

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source
destination

Chain OUTPUT (policy ACCEPT 260 packets, 35768 bytes)
 pkts bytes target     prot opt in     out     source
destination

Chain f2b-sshd (1 references)
 pkts bytes target     prot opt in     out     source
destination
   22  1768 REJECT     all  --  *      *       43.154.179.253
0.0.0.0/0            reject-with icmp-port-unreachable
 1069  126K RETURN     all  --  *      *       0.0.0.0/0
0.0.0.0/0

> and ``iptables -S`` ?

-P INPUT ACCEPT
-P FORWARD ACCEPT
-P OUTPUT ACCEPT
-N f2b-sshd
-A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd
-A f2b-sshd -s 61.177.173.50/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 61.177.173.7/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 43.154.179.253/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -j RETURN

[toc] | [prev] | [next] | [standalone]


#248538

FromIL Ka <kazakevichilya@gmail.com>
Date2022-05-29 18:40 +0200
Message-ID<Esu7n-19a1-1@gated-at.bofh.it>
In reply to#248536

[Multipart message — attachments visible in raw view] — view raw

>
>
> > and ``iptables -S`` ?
>
> -P INPUT ACCEPT
> -P FORWARD ACCEPT
> -P OUTPUT ACCEPT
> -N f2b-sshd
> -A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd
> -A f2b-sshd -s 61.177.173.50/32 -j REJECT --reject-with
> icmp-port-unreachable
> -A f2b-sshd -s 61.177.173.7/32 -j REJECT --reject-with
> icmp-port-unreachable
> -A f2b-sshd -s 43.154.179.253/32 -j REJECT --reject-with
> icmp-port-unreachable
> -A f2b-sshd -j RETURN
>

I do not see any rule that returns "no route to host".

You can use ``tcmpdump`` to see who is answering "no route to host" for
your "telnet [ip] 80" session.
I am pretty sure this is not your firewall problem

[toc] | [prev] | [next] | [standalone]


#248539

FromIL Ka <kazakevichilya@gmail.com>
Date2022-05-29 18:40 +0200
Message-ID<Esu7n-19a1-11@gated-at.bofh.it>
In reply to#248536

[Multipart message — attachments visible in raw view] — view raw

btw, are you able to ping server?

On Sun, May 29, 2022 at 7:26 PM Tom Browder <tom.browder@gmail.com> wrote:

> On Sun, May 29, 2022 at 10:33 AM IL Ka <kazakevichilya@gmail.com> wrote:
> >
> >
> >> When running those, I'm told neither the arptablrs nor the ebtables are
> registered (not installed). Should I install them?
> >
> > No.
> >
> > So, you now have legacy (classic) iptables, right?
>
> Yes.
>
> > What is the output of ``iptables -L -v -n``
>
> Chain INPUT (policy ACCEPT 279 packets, 36670 bytes)
>  pkts bytes target     prot opt in     out     source
> destination
>  1387  150K f2b-sshd   tcp  --  *      *       0.0.0.0/0
> 0.0.0.0/0            multiport dports 22
>
> Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
>  pkts bytes target     prot opt in     out     source
> destination
>
> Chain OUTPUT (policy ACCEPT 260 packets, 35768 bytes)
>  pkts bytes target     prot opt in     out     source
> destination
>
> Chain f2b-sshd (1 references)
>  pkts bytes target     prot opt in     out     source
> destination
>    22  1768 REJECT     all  --  *      *       43.154.179.253
> 0.0.0.0/0            reject-with icmp-port-unreachable
>  1069  126K RETURN     all  --  *      *       0.0.0.0/0
> 0.0.0.0/0
>
> > and ``iptables -S`` ?
>
> -P INPUT ACCEPT
> -P FORWARD ACCEPT
> -P OUTPUT ACCEPT
> -N f2b-sshd
> -A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd
> -A f2b-sshd -s 61.177.173.50/32 -j REJECT --reject-with
> icmp-port-unreachable
> -A f2b-sshd -s 61.177.173.7/32 -j REJECT --reject-with
> icmp-port-unreachable
> -A f2b-sshd -s 43.154.179.253/32 -j REJECT --reject-with
> icmp-port-unreachable
> -A f2b-sshd -j RETURN
>

[toc] | [prev] | [next] | [standalone]


#248541

FromTom Browder <tom.browder@gmail.com>
Date2022-05-29 19:30 +0200
Message-ID<EsuTL-19In-1@gated-at.bofh.it>
In reply to#248539

[Multipart message — attachments visible in raw view] — view raw

On Sun, May 29, 2022 at 11:39 IL Ka <kazakevichilya@gmail.com> wrote:

> btw, are you able to ping server?
>

Yes.

[toc] | [prev] | [next] | [standalone]


#248543

Fromjohn doe <johndoe65534@mail.com>
Date2022-05-29 20:30 +0200
Message-ID<EsvPQ-1ajn-37@gated-at.bofh.it>
In reply to#248541
On 5/29/2022 7:20 PM, Tom Browder wrote:
> On Sun, May 29, 2022 at 11:39 IL Ka <kazakevichilya@gmail.com> wrote:
>
>> btw, are you able to ping server?
>>
>
> Yes.
>

It is always better to show the command and the output instead of saying
yes/no! :)

I must say, I can not realy understand how you can ping and not
telnet/access your web server.

--
John Doe

[toc] | [prev] | [next] | [standalone]


#248545

FromIL Ka <kazakevichilya@gmail.com>
Date2022-05-29 21:00 +0200
Message-ID<EswiR-1axC-5@gated-at.bofh.it>
In reply to#248543

[Multipart message — attachments visible in raw view] — view raw

>
>
> I must say, I can not realy understand how you can ping and not
> telnet/access your web server.
>
>
Some router between OP and his server has something like

-I FORWARD -j REJECT --reject-with icmp-host-unreachable

[toc] | [prev] | [next] | [standalone]


#248546

FromGreg Wooledge <greg@wooledge.org>
Date2022-05-29 21:30 +0200
Message-ID<EswLT-1aWh-3@gated-at.bofh.it>
In reply to#248543
> > > btw, are you able to ping server?
> > 
> > Yes.
> 
> It is always better to show the command and the output instead of saying
> yes/no! :)

Except it should be abundantly clear by now that you're dealing with
someone who believes that they must hide every single detail from
the ones who would offer help.

Never mind that the details are REQUIRED to diagnose the problem.

What's important is that their WEB SERVER which is by definition supposed
to be AVAILABLE TO THE ENTIRE WORLD must remain secret and hidden from
the people trying to help.

Have fun continuing to try pulling teeth on this.

[toc] | [prev] | [next] | [standalone]


#248547

FromTom Browder <tom.browder@gmail.com>
Date2022-05-29 22:50 +0200
Message-ID<Esy1j-1bAu-1@gated-at.bofh.it>
In reply to#248546
On Sun, May 29, 2022 at 2:21 PM Greg Wooledge <greg@wooledge.org> wrote:
>
> > > > btw, are you able to ping server?
> > >
> > > Yes.
> >
> > It is always better to show the command and the output instead of saying
> > yes/no! :)
>
> Except it should be abundantly clear by now that you're dealing with
> someone who believes that they must hide every single detail from
> the ones who would offer help.

I have not intentionally hidden anything, Greg--I just never saw the need for
mentioning it given the dialogue--x.y.z.w is just shorthand. If you
must know the exact IP address, it is 69.30.225.10. (And you could have
asked for it at any time--I don't remember anyone asking for it--but I will
do so the next time I ask for this kind of help again.)

GIven all the advice, I'm leaning towards the popular hypothesis that
my provider has somehow locked out the two ports in question (a first
for them). The machine is now inaccessible, and I have asked them to
reinstall Debian 11 on it and ENSURE that ports 80 and 443 are
accessible from the internet.

Thanks for all the help, and I consider this thread closed.

-Tom

[toc] | [prev] | [next] | [standalone]


#248548

FromGreg Wooledge <greg@wooledge.org>
Date2022-05-29 23:00 +0200
Message-ID<EsyaZ-1bDz-7@gated-at.bofh.it>
In reply to#248547
On Sun, May 29, 2022 at 03:39:05PM -0500, Tom Browder wrote:
> I have not intentionally hidden anything, Greg--I just never saw the need for
> mentioning it given the dialogue--x.y.z.w is just shorthand. If you
> must know the exact IP address, it is 69.30.225.10.

OK.  Now we can actually start helping.

First of all, this is a regular old routable IPv4 address.  It's not one
of the non-routables, like 192.168.* or 10.*.  This is good.  It
eliminates a whole class of problems like "My machine's IP address says
192.168.1.2 but I can't reach it from outside my network", all of which
were still on the table until now.

Second, I cannot ping this IP address, nor can I telnet to port 80 of it.
(Nor port 22.)

I don't get an error, though -- just a hang/timeout.

If you can ping this, or ssh to it, or reach it on ANY port at all,
from the public Internet, then that's a huge red flag pointing to a
firewall that filters incoming connections based on source IP.  Such
a firewall could be on the host itself, or on a router which protects
the host.

If you can't do any of those things, then we don't get as much information
out of it.  It could simply be the wrong IP address for all we know
at that point.  Or it could be a misconfigured firewall, or the machine
could be crashed, or the network cable fell out, or any number of other
issues.

[toc] | [prev] | [next] | [standalone]


#248550

FromTom Browder <tom.browder@gmail.com>
Date2022-05-30 00:30 +0200
Message-ID<EszA5-1cAU-3@gated-at.bofh.it>
In reply to#248548

[Multipart message — attachments visible in raw view] — view raw

On Sun, May 29, 2022 at 15:55 Greg Wooledge <greg@wooledge.org> wrote:
...

Thanks, Greg. It looks like my server was blocked from ports 80 and 443
upstream from it (as you and others suspected), so I asked my provider to
reinstall the OS and ensure it has public access to ports 80 and 443.

Best regards,

-Tom

[toc] | [prev] | [next] | [standalone]


Page 1 of 3  [1] 2 3  Next page →

Back to top | Article view | linux.debian.user


csiph-web