Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #248501 > unrolled thread
| Started by | Tom Browder <tom.browder@gmail.com> |
|---|---|
| First post | 2022-05-28 21:20 +0200 |
| Last post | 2022-05-29 00:30 +0200 |
| Articles | 20 on this page of 56 — 13 participants |
Back to article view | Back to linux.debian.user
Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-28 21:20 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Dan Ritter <dsr@randomstring.org> - 2022-05-28 21:40 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Georgi Naplatanov <gosho@oles.biz> - 2022-05-28 21:50 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-28 22:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-28 23:10 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 00:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 17:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 17:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 17:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 17:40 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 18:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 18:40 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 18:40 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 19:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 john doe <johndoe65534@mail.com> - 2022-05-29 20:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 21:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-29 21:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 22:50 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-29 23:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-30 00:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 john doe <johndoe65534@mail.com> - 2022-05-30 09:20 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-30 14:20 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-30 15:50 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-30 16:10 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-30 19:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2022-05-31 01:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-30 19:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Edwin Zimmerman <edwin@plainemail.net> - 2022-05-31 02:50 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-06-01 13:50 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 john doe <johndoe65534@mail.com> - 2022-06-01 18:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-06-01 19:20 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Lee <ler762@gmail.com> - 2022-05-30 02:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-30 02:20 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2022-05-30 02:40 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-30 02:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Curt <curty@free.fr> - 2022-05-30 14:10 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 00:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 00:40 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 01:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 02:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Timothy M Butterworth <timothy.m.butterworth@gmail.com> - 2022-05-29 02:20 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 02:40 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Charles Kroeger <mbone@gmx.co.uk> - 2022-05-30 07:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Greg Wooledge <greg@wooledge.org> - 2022-05-29 02:10 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 02:20 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 03:10 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 04:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 12:50 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 13:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 14:10 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Tom Browder <tom.browder@gmail.com> - 2022-05-29 14:30 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 14:50 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Erwan David <erwan@rail.eu.org> - 2022-05-29 16:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 IL Ka <kazakevichilya@gmail.com> - 2022-05-29 14:10 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 <tomas@tuxteam.de> - 2022-05-29 19:00 +0200
Re: Firewall blocking my new Debian 11 server ports 80 and 443 Dan Ritter <dsr@randomstring.org> - 2022-05-29 00:30 +0200
Page 1 of 3 [1] 2 3 Next page →
| From | Tom Browder <tom.browder@gmail.com> |
|---|---|
| Date | 2022-05-28 21:20 +0200 |
| Subject | Firewall blocking my new Debian 11 server ports 80 and 443 |
| Message-ID | <Esa8G-XdI-19@gated-at.bofh.it> |
As the bare-iron server came from my long-time cloud provider (since
Debian 6), incoming ports 80 and 443 are blocked.
I ran my usual iptables command for new servers from them, but this
time the default settings were different so it didn't work.
Output from "sudo iptables -S" before my attempt:
-P INPUT ACCEPT
-P FORWARD ACCEPT
-P OUTPUT ACCEPT
-N f2b-sshd
-A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd
-A f2b-sshd -s 62.204.41.56/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 61.177.173.48/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 167.172.187.120/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 43.156.124.69/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 43.154.46.209/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 61.177.172.98/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 122.160.233.137/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -j RETURN
My usual incantation and response:
# sudo iptables -A IN_public_allow -p tcp -m tcp --dport 80 -m
conntrack --ctstate NEW,UNTRACKED -j ACCEPT
iptables: No chain/target/match by that name.
Then I tried:
# sudo iptables -A INPUT -p tcp -m tcp --dport 80 -m conntrack
--ctstate NEW,UNTRACKED -j ACCEPT
# sudo iptables -A INPUT -p tcp -m tcp --dport 443 -m conntrack
--ctstate NEW,UNTRACKED -j ACCEPT
Again checking status:
# sudo iptables -S
-P INPUT ACCEPT
-P FORWARD ACCEPT
-P OUTPUT ACCEPT
-N f2b-sshd
-A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd
-A INPUT -p tcp -m tcp --dport 80 -m conntrack --ctstate NEW,UNTRACKED -j ACCEPT
-A INPUT -p tcp -m tcp --dport 443 -m conntrack --ctstate
NEW,UNTRACKED -j ACCEPT
-A INPUT -p tcp -m tcp --dport 80 -m conntrack --ctstate NEW,UNTRACKED -j ACCEPT
-A f2b-sshd -s 62.204.41.56/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 61.177.173.48/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 167.172.187.120/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 43.156.124.69/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 43.154.46.209/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 61.177.172.98/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -s 122.160.233.137/32 -j REJECT --reject-with icmp-port-unreachable
-A f2b-sshd -j RETURN
But no open ports in spite of the output shown.
I am considering moving to ufw but am reluctant due to the possibility
of getting locked-out of my remote server. I am used to logging in
with two separate terminals to avoid that during initial setup but
want to make sure that is safe.
Suggestions welcome!
-Tom
[toc] | [next] | [standalone]
| From | Dan Ritter <dsr@randomstring.org> |
|---|---|
| Date | 2022-05-28 21:40 +0200 |
| Message-ID | <Esas1-XjK-3@gated-at.bofh.it> |
| In reply to | #248501 |
Tom Browder wrote: > As the bare-iron server came from my long-time cloud provider (since > Debian 6), incoming ports 80 and 443 are blocked. > > I ran my usual iptables command for new servers from them, but this > time the default settings were different so it didn't work. > > Output from "sudo iptables -S" before my attempt: > > -P INPUT ACCEPT > -P FORWARD ACCEPT > -P OUTPUT ACCEPT > -N f2b-sshd > -A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd > -A f2b-sshd -s 62.204.41.56/32 -j REJECT --reject-with icmp-port-unreachable > -A f2b-sshd -s 61.177.173.48/32 -j REJECT --reject-with icmp-port-unreachable > -A f2b-sshd -s 167.172.187.120/32 -j REJECT --reject-with icmp-port-unreachable > -A f2b-sshd -s 43.156.124.69/32 -j REJECT --reject-with icmp-port-unreachable > -A f2b-sshd -s 43.154.46.209/32 -j REJECT --reject-with icmp-port-unreachable > -A f2b-sshd -s 61.177.172.98/32 -j REJECT --reject-with icmp-port-unreachable > -A f2b-sshd -s 122.160.233.137/32 -j REJECT --reject-with icmp-port-unreachable > -A f2b-sshd -j RETURN This is strongly suggestive of having fail2ban installed. The -P statements set default policy for each of the default chains: if nothing else happens to a packet, that's the policy. > My usual incantation and response: > > # sudo iptables -A IN_public_allow -p tcp -m tcp --dport 80 -m > conntrack --ctstate NEW,UNTRACKED -j ACCEPT > iptables: No chain/target/match by that name. IN_public_allow hasn't been created and isn't a default. > Then I tried: > > # sudo iptables -A INPUT -p tcp -m tcp --dport 80 -m conntrack > --ctstate NEW,UNTRACKED -j ACCEPT > # sudo iptables -A INPUT -p tcp -m tcp --dport 443 -m conntrack > --ctstate NEW,UNTRACKED -j ACCEPT Which is fine, but remember that the default policies all the way around are ACCEPT, so this doesn't change anything until you change the policy. > Again checking status: [normal output] > But no open ports in spite of the output shown. 1. How are you checking that? 2. Have you asked the cloud provider if they need an extra step on their end to open up the ports? It's likely on their side. > I am considering moving to ufw but am reluctant due to the possibility > of getting locked-out of my remote server. I am used to logging in > with two separate terminals to avoid that during initial setup but > want to make sure that is safe. The cloud provider should provide console access via emulated serial port or similar for you to get in without going through the VM's network. -dsr-
[toc] | [prev] | [next] | [standalone]
| From | Georgi Naplatanov <gosho@oles.biz> |
|---|---|
| Date | 2022-05-28 21:50 +0200 |
| Message-ID | <EsaBH-Xnw-29@gated-at.bofh.it> |
| In reply to | #248501 |
On 5/28/22 22:11, Tom Browder wrote: > As the bare-iron server came from my long-time cloud provider (since > Debian 6), incoming ports 80 and 443 are blocked. > > I ran my usual iptables command for new servers from them, but this > time the default settings were different so it didn't work. Try to flush the tables and (re)set default policies for the existing chains. > Output from "sudo iptables -S" before my attempt: > > -P INPUT ACCEPT > -P FORWARD ACCEPT > -P OUTPUT ACCEPT > -N f2b-sshd > -A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd > -A f2b-sshd -s 62.204.41.56/32 -j REJECT --reject-with icmp-port-unreachable > -A f2b-sshd -s 61.177.173.48/32 -j REJECT --reject-with icmp-port-unreachable > -A f2b-sshd -s 167.172.187.120/32 -j REJECT --reject-with icmp-port-unreachable > -A f2b-sshd -s 43.156.124.69/32 -j REJECT --reject-with icmp-port-unreachable > -A f2b-sshd -s 43.154.46.209/32 -j REJECT --reject-with icmp-port-unreachable > -A f2b-sshd -s 61.177.172.98/32 -j REJECT --reject-with icmp-port-unreachable > -A f2b-sshd -s 122.160.233.137/32 -j REJECT --reject-with icmp-port-unreachable > -A f2b-sshd -j RETURN > > My usual incantation and response: > > # sudo iptables -A IN_public_allow -p tcp -m tcp --dport 80 -m > conntrack --ctstate NEW,UNTRACKED -j ACCEPT > iptables: No chain/target/match by that name. You have no chain "IN_public_allow". Probably you should create it. > Then I tried: > > # sudo iptables -A INPUT -p tcp -m tcp --dport 80 -m conntrack > --ctstate NEW,UNTRACKED -j ACCEPT > # sudo iptables -A INPUT -p tcp -m tcp --dport 443 -m conntrack > --ctstate NEW,UNTRACKED -j ACCEPT It's a good practice to set input/output network interfaces. > Again checking status: > > # sudo iptables -S > -P INPUT ACCEPT > -P FORWARD ACCEPT > -P OUTPUT ACCEPT > -N f2b-sshd > -A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd > -A INPUT -p tcp -m tcp --dport 80 -m conntrack --ctstate NEW,UNTRACKED -j ACCEPT > -A INPUT -p tcp -m tcp --dport 443 -m conntrack --ctstate > NEW,UNTRACKED -j ACCEPT > -A INPUT -p tcp -m tcp --dport 80 -m conntrack --ctstate NEW,UNTRACKED -j ACCEPT You have second rule for port 80/tcp, do you need it? > -A f2b-sshd -s 62.204.41.56/32 -j REJECT --reject-with icmp-port-unreachable > -A f2b-sshd -s 61.177.173.48/32 -j REJECT --reject-with icmp-port-unreachable > -A f2b-sshd -s 167.172.187.120/32 -j REJECT --reject-with icmp-port-unreachable > -A f2b-sshd -s 43.156.124.69/32 -j REJECT --reject-with icmp-port-unreachable > -A f2b-sshd -s 43.154.46.209/32 -j REJECT --reject-with icmp-port-unreachable > -A f2b-sshd -s 61.177.172.98/32 -j REJECT --reject-with icmp-port-unreachable > -A f2b-sshd -s 122.160.233.137/32 -j REJECT --reject-with icmp-port-unreachable > -A f2b-sshd -j RETURN > > But no open ports in spite of the output shown. > > I am considering moving to ufw but am reluctant due to the possibility > of getting locked-out of my remote server. I am used to logging in > with two separate terminals to avoid that during initial setup but > want to make sure that is safe. > Kind regards Georgi
[toc] | [prev] | [next] | [standalone]
| From | IL Ka <kazakevichilya@gmail.com> |
|---|---|
| Date | 2022-05-28 22:00 +0200 |
| Message-ID | <EsaLn-XqP-9@gated-at.bofh.it> |
| In reply to | #248501 |
[Multipart message — attachments visible in raw view] — view raw
> > > > -P INPUT ACCEPT > -P FORWARD ACCEPT > -P OUTPUT ACCEPT > -N f2b-sshd > -A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd > -A f2b-sshd -s 62.204.41.56/32 -j REJECT --reject-with > icmp-port-unreachable > -A f2b-sshd -s 61.177.173.48/32 -j REJECT --reject-with > icmp-port-unreachable > -A f2b-sshd -s 167.172.187.120/32 -j REJECT --reject-with > icmp-port-unreachable > -A f2b-sshd -s 43.156.124.69/32 -j REJECT --reject-with > icmp-port-unreachable > -A f2b-sshd -s 43.154.46.209/32 -j REJECT --reject-with > icmp-port-unreachable > -A f2b-sshd -s 61.177.172.98/32 -j REJECT --reject-with > icmp-port-unreachable > -A f2b-sshd -s 122.160.233.137/32 -j REJECT --reject-with > icmp-port-unreachable > -A f2b-sshd -j RETURN > This is fail2ban chain to block bots, but I strongly suggest to use ipset and not to store each network as separate rule. On my Debian server I use netfilter-persistent with ipset plugin and fail2ban. Works like charm! https://dhtar.com/make-ipset-and-iptables-configurations-persistent-in-debianubuntu.html <https://dhtar.com/make-ipset-and-iptables-configurations-persistent-in-debianubuntu.html> But since policy is "ACCEPT", other ports are open. > My usual incantation and response: > > # sudo iptables -A IN_public_allow -p tcp -m tcp --dport 80 -m > conntrack --ctstate NEW,UNTRACKED -j ACCEPT > iptables: No chain/target/match by that name. > > What is "IN_public_allow" I do not see chain with this name. Do you? > # sudo iptables -S > -P INPUT ACCEPT > -P FORWARD ACCEPT > -P OUTPUT ACCEPT > -N f2b-sshd > -A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd > -A INPUT -p tcp -m tcp --dport 80 -m conntrack --ctstate NEW,UNTRACKED -j > ACCEPT > -A INPUT -p tcp -m tcp --dport 443 -m conntrack --ctstate > ... > But no open ports in spite of the output shown. > Hmm, I see 80 and 443 are open here. How did you check? (I suggest to use multiple ports rule (multiport), btw) > I am considering moving to ufw It is up to you. I see no reason to use ufw. At least, it doesn't support ipset:) Also, check (using update-alternatives) if you are using iptables of nft You may be interested in good iptables tutorial: https://tldp.org/LDP/nag2/nag2.pdf (section 9.8)
[toc] | [prev] | [next] | [standalone]
| From | Tom Browder <tom.browder@gmail.com> |
|---|---|
| Date | 2022-05-28 23:10 +0200 |
| Message-ID | <EsbR7-Yhw-7@gated-at.bofh.it> |
| In reply to | #248501 |
[Multipart message — attachments visible in raw view] — view raw
On Sat, May 28, 2022 at 14:11 Tom Browder <tom.browder@gmail.com> wrote: > As the bare-iron server came from my long-time cloud provider (since > Debian 6), incoming ports 80 and 443 are blocked. A little more digging shows the new server is using fail2ban and nft tables, so I need help on how to properly allow https and http inbound. Thanks. -Tom
[toc] | [prev] | [next] | [standalone]
| From | IL Ka <kazakevichilya@gmail.com> |
|---|---|
| Date | 2022-05-29 00:30 +0200 |
| Message-ID | <Esd6x-YVu-1@gated-at.bofh.it> |
| In reply to | #248507 |
[Multipart message — attachments visible in raw view] — view raw
> > > > A little more digging shows the new server is using fail2ban and nft > tables, so I > need help on how to properly allow https and http inbound. > > I am not familiar with nft, bit you can switch to iptables using ``update-alternatives`` # update-alternatives --set iptables /usr/sbin/iptables-legacy # update-alternatives --set ip6tables /usr/sbin/ip6tables-legacy # update-alternatives --set arptables /usr/sbin/arptables-legacy # update-alternatives --set ebtables /usr/sbin/ebtables-legacy I am using iptables on my servers. nfs is good, but I do not have time (for now) to learn it
[toc] | [prev] | [next] | [standalone]
| From | Tom Browder <tom.browder@gmail.com> |
|---|---|
| Date | 2022-05-29 17:00 +0200 |
| Message-ID | <EssyB-183s-3@gated-at.bofh.it> |
| In reply to | #248510 |
[Multipart message — attachments visible in raw view] — view raw
On Sat, May 28, 2022 at 17:24 IL Ka <kazakevichilya@gmail.com> wrote: > ... I am not familiar with nft, bit you can switch to iptables using >> ``update-alternatives`` >> > > # update-alternatives --set iptables /usr/sbin/iptables-legacy > # update-alternatives --set ip6tables /usr/sbin/ip6tables-legacy > # update-alternatives --set arptables /usr/sbin/arptables-legacy > # update-alternatives --set ebtables /usr/sbin/ebtables-legacy > Do I have to switch all four *legacy *tables? -Tom
[toc] | [prev] | [next] | [standalone]
| From | IL Ka <kazakevichilya@gmail.com> |
|---|---|
| Date | 2022-05-29 17:00 +0200 |
| Message-ID | <EssyB-183s-1@gated-at.bofh.it> |
| In reply to | #248531 |
[Multipart message — attachments visible in raw view] — view raw
> > >> Do I have to switch all four *legacy *tables? > yes
[toc] | [prev] | [next] | [standalone]
| From | Tom Browder <tom.browder@gmail.com> |
|---|---|
| Date | 2022-05-29 17:30 +0200 |
| Message-ID | <Est1D-18rL-3@gated-at.bofh.it> |
| In reply to | #248532 |
[Multipart message — attachments visible in raw view] — view raw
On Sun, May 29, 2022 at 09:51 IL Ka <kazakevichilya@gmail.com> wrote: > >>> Do I have to switch all four *legacy *tables? >> > > yes > When running those, I'm told neither the arptablrs nor the ebtables are registered (not installed). Should I install them? >
[toc] | [prev] | [next] | [standalone]
| From | IL Ka <kazakevichilya@gmail.com> |
|---|---|
| Date | 2022-05-29 17:40 +0200 |
| Message-ID | <Estbk-18uQ-9@gated-at.bofh.it> |
| In reply to | #248534 |
[Multipart message — attachments visible in raw view] — view raw
> When running those, I'm told neither the arptablrs nor the ebtables are > registered (not installed). Should I install them? > No. So, you now have legacy (classic) iptables, right? What is the output of ``iptables -L -v -n`` and ``iptables -S`` ?
[toc] | [prev] | [next] | [standalone]
| From | Tom Browder <tom.browder@gmail.com> |
|---|---|
| Date | 2022-05-29 18:30 +0200 |
| Message-ID | <EstXH-196K-1@gated-at.bofh.it> |
| In reply to | #248535 |
On Sun, May 29, 2022 at 10:33 AM IL Ka <kazakevichilya@gmail.com> wrote: > > >> When running those, I'm told neither the arptablrs nor the ebtables are registered (not installed). Should I install them? > > No. > > So, you now have legacy (classic) iptables, right? Yes. > What is the output of ``iptables -L -v -n`` Chain INPUT (policy ACCEPT 279 packets, 36670 bytes) pkts bytes target prot opt in out source destination 1387 150K f2b-sshd tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport dports 22 Chain FORWARD (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination Chain OUTPUT (policy ACCEPT 260 packets, 35768 bytes) pkts bytes target prot opt in out source destination Chain f2b-sshd (1 references) pkts bytes target prot opt in out source destination 22 1768 REJECT all -- * * 43.154.179.253 0.0.0.0/0 reject-with icmp-port-unreachable 1069 126K RETURN all -- * * 0.0.0.0/0 0.0.0.0/0 > and ``iptables -S`` ? -P INPUT ACCEPT -P FORWARD ACCEPT -P OUTPUT ACCEPT -N f2b-sshd -A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd -A f2b-sshd -s 61.177.173.50/32 -j REJECT --reject-with icmp-port-unreachable -A f2b-sshd -s 61.177.173.7/32 -j REJECT --reject-with icmp-port-unreachable -A f2b-sshd -s 43.154.179.253/32 -j REJECT --reject-with icmp-port-unreachable -A f2b-sshd -j RETURN
[toc] | [prev] | [next] | [standalone]
| From | IL Ka <kazakevichilya@gmail.com> |
|---|---|
| Date | 2022-05-29 18:40 +0200 |
| Message-ID | <Esu7n-19a1-1@gated-at.bofh.it> |
| In reply to | #248536 |
[Multipart message — attachments visible in raw view] — view raw
> > > > and ``iptables -S`` ? > > -P INPUT ACCEPT > -P FORWARD ACCEPT > -P OUTPUT ACCEPT > -N f2b-sshd > -A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd > -A f2b-sshd -s 61.177.173.50/32 -j REJECT --reject-with > icmp-port-unreachable > -A f2b-sshd -s 61.177.173.7/32 -j REJECT --reject-with > icmp-port-unreachable > -A f2b-sshd -s 43.154.179.253/32 -j REJECT --reject-with > icmp-port-unreachable > -A f2b-sshd -j RETURN > I do not see any rule that returns "no route to host". You can use ``tcmpdump`` to see who is answering "no route to host" for your "telnet [ip] 80" session. I am pretty sure this is not your firewall problem
[toc] | [prev] | [next] | [standalone]
| From | IL Ka <kazakevichilya@gmail.com> |
|---|---|
| Date | 2022-05-29 18:40 +0200 |
| Message-ID | <Esu7n-19a1-11@gated-at.bofh.it> |
| In reply to | #248536 |
[Multipart message — attachments visible in raw view] — view raw
btw, are you able to ping server? On Sun, May 29, 2022 at 7:26 PM Tom Browder <tom.browder@gmail.com> wrote: > On Sun, May 29, 2022 at 10:33 AM IL Ka <kazakevichilya@gmail.com> wrote: > > > > > >> When running those, I'm told neither the arptablrs nor the ebtables are > registered (not installed). Should I install them? > > > > No. > > > > So, you now have legacy (classic) iptables, right? > > Yes. > > > What is the output of ``iptables -L -v -n`` > > Chain INPUT (policy ACCEPT 279 packets, 36670 bytes) > pkts bytes target prot opt in out source > destination > 1387 150K f2b-sshd tcp -- * * 0.0.0.0/0 > 0.0.0.0/0 multiport dports 22 > > Chain FORWARD (policy ACCEPT 0 packets, 0 bytes) > pkts bytes target prot opt in out source > destination > > Chain OUTPUT (policy ACCEPT 260 packets, 35768 bytes) > pkts bytes target prot opt in out source > destination > > Chain f2b-sshd (1 references) > pkts bytes target prot opt in out source > destination > 22 1768 REJECT all -- * * 43.154.179.253 > 0.0.0.0/0 reject-with icmp-port-unreachable > 1069 126K RETURN all -- * * 0.0.0.0/0 > 0.0.0.0/0 > > > and ``iptables -S`` ? > > -P INPUT ACCEPT > -P FORWARD ACCEPT > -P OUTPUT ACCEPT > -N f2b-sshd > -A INPUT -p tcp -m multiport --dports 22 -j f2b-sshd > -A f2b-sshd -s 61.177.173.50/32 -j REJECT --reject-with > icmp-port-unreachable > -A f2b-sshd -s 61.177.173.7/32 -j REJECT --reject-with > icmp-port-unreachable > -A f2b-sshd -s 43.154.179.253/32 -j REJECT --reject-with > icmp-port-unreachable > -A f2b-sshd -j RETURN >
[toc] | [prev] | [next] | [standalone]
| From | Tom Browder <tom.browder@gmail.com> |
|---|---|
| Date | 2022-05-29 19:30 +0200 |
| Message-ID | <EsuTL-19In-1@gated-at.bofh.it> |
| In reply to | #248539 |
[Multipart message — attachments visible in raw view] — view raw
On Sun, May 29, 2022 at 11:39 IL Ka <kazakevichilya@gmail.com> wrote: > btw, are you able to ping server? > Yes.
[toc] | [prev] | [next] | [standalone]
| From | john doe <johndoe65534@mail.com> |
|---|---|
| Date | 2022-05-29 20:30 +0200 |
| Message-ID | <EsvPQ-1ajn-37@gated-at.bofh.it> |
| In reply to | #248541 |
On 5/29/2022 7:20 PM, Tom Browder wrote: > On Sun, May 29, 2022 at 11:39 IL Ka <kazakevichilya@gmail.com> wrote: > >> btw, are you able to ping server? >> > > Yes. > It is always better to show the command and the output instead of saying yes/no! :) I must say, I can not realy understand how you can ping and not telnet/access your web server. -- John Doe
[toc] | [prev] | [next] | [standalone]
| From | IL Ka <kazakevichilya@gmail.com> |
|---|---|
| Date | 2022-05-29 21:00 +0200 |
| Message-ID | <EswiR-1axC-5@gated-at.bofh.it> |
| In reply to | #248543 |
[Multipart message — attachments visible in raw view] — view raw
> > > I must say, I can not realy understand how you can ping and not > telnet/access your web server. > > Some router between OP and his server has something like -I FORWARD -j REJECT --reject-with icmp-host-unreachable
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <greg@wooledge.org> |
|---|---|
| Date | 2022-05-29 21:30 +0200 |
| Message-ID | <EswLT-1aWh-3@gated-at.bofh.it> |
| In reply to | #248543 |
> > > btw, are you able to ping server? > > > > Yes. > > It is always better to show the command and the output instead of saying > yes/no! :) Except it should be abundantly clear by now that you're dealing with someone who believes that they must hide every single detail from the ones who would offer help. Never mind that the details are REQUIRED to diagnose the problem. What's important is that their WEB SERVER which is by definition supposed to be AVAILABLE TO THE ENTIRE WORLD must remain secret and hidden from the people trying to help. Have fun continuing to try pulling teeth on this.
[toc] | [prev] | [next] | [standalone]
| From | Tom Browder <tom.browder@gmail.com> |
|---|---|
| Date | 2022-05-29 22:50 +0200 |
| Message-ID | <Esy1j-1bAu-1@gated-at.bofh.it> |
| In reply to | #248546 |
On Sun, May 29, 2022 at 2:21 PM Greg Wooledge <greg@wooledge.org> wrote: > > > > > btw, are you able to ping server? > > > > > > Yes. > > > > It is always better to show the command and the output instead of saying > > yes/no! :) > > Except it should be abundantly clear by now that you're dealing with > someone who believes that they must hide every single detail from > the ones who would offer help. I have not intentionally hidden anything, Greg--I just never saw the need for mentioning it given the dialogue--x.y.z.w is just shorthand. If you must know the exact IP address, it is 69.30.225.10. (And you could have asked for it at any time--I don't remember anyone asking for it--but I will do so the next time I ask for this kind of help again.) GIven all the advice, I'm leaning towards the popular hypothesis that my provider has somehow locked out the two ports in question (a first for them). The machine is now inaccessible, and I have asked them to reinstall Debian 11 on it and ENSURE that ports 80 and 443 are accessible from the internet. Thanks for all the help, and I consider this thread closed. -Tom
[toc] | [prev] | [next] | [standalone]
| From | Greg Wooledge <greg@wooledge.org> |
|---|---|
| Date | 2022-05-29 23:00 +0200 |
| Message-ID | <EsyaZ-1bDz-7@gated-at.bofh.it> |
| In reply to | #248547 |
On Sun, May 29, 2022 at 03:39:05PM -0500, Tom Browder wrote: > I have not intentionally hidden anything, Greg--I just never saw the need for > mentioning it given the dialogue--x.y.z.w is just shorthand. If you > must know the exact IP address, it is 69.30.225.10. OK. Now we can actually start helping. First of all, this is a regular old routable IPv4 address. It's not one of the non-routables, like 192.168.* or 10.*. This is good. It eliminates a whole class of problems like "My machine's IP address says 192.168.1.2 but I can't reach it from outside my network", all of which were still on the table until now. Second, I cannot ping this IP address, nor can I telnet to port 80 of it. (Nor port 22.) I don't get an error, though -- just a hang/timeout. If you can ping this, or ssh to it, or reach it on ANY port at all, from the public Internet, then that's a huge red flag pointing to a firewall that filters incoming connections based on source IP. Such a firewall could be on the host itself, or on a router which protects the host. If you can't do any of those things, then we don't get as much information out of it. It could simply be the wrong IP address for all we know at that point. Or it could be a misconfigured firewall, or the machine could be crashed, or the network cable fell out, or any number of other issues.
[toc] | [prev] | [next] | [standalone]
| From | Tom Browder <tom.browder@gmail.com> |
|---|---|
| Date | 2022-05-30 00:30 +0200 |
| Message-ID | <EszA5-1cAU-3@gated-at.bofh.it> |
| In reply to | #248548 |
[Multipart message — attachments visible in raw view] — view raw
On Sun, May 29, 2022 at 15:55 Greg Wooledge <greg@wooledge.org> wrote: ... Thanks, Greg. It looks like my server was blocked from ports 80 and 443 upstream from it (as you and others suspected), so I asked my provider to reinstall the OS and ensure it has public access to ports 80 and 443. Best regards, -Tom
[toc] | [prev] | [next] | [standalone]
Page 1 of 3 [1] 2 3 Next page →
Back to top | Article view | linux.debian.user
csiph-web