From: Francis Cianfrocca Date: 2006-10-04T08:04:46+09:00 Subject: Re: NET::HTTP behind a firewall? ------=_Part_16360_28485399.1159916683001 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Content-Disposition: inline On 10/3/06, Joe Regular wrote: > > Joe Regular wrote: # TCP OUT # for tcp_out in $TCP_OUT; do $IPTABLES -A OUTPUT -o $PUB_IFACE -p tcp -m state --state NEW --sport $UNPRIVPORTS --dport $tcp_out -j ACCEPT done Is your routing is configured such that your external servers are reachable through eth1? Can you ping anything from this server? Can you telnet to the affected external web servers on port 80? Can you traceroute to them (either using ICMP or UDP)? Did your code work correctly on a test server that didn't have this firewall config? What's the output from iptables -L? As far as the local (ephemeral) port is concerned, this rule will let anything out that is locally bound to any port higher than 1024, which should be ok. ------=_Part_16360_28485399.1159916683001--