From: Joe Regular Date: 2006-10-04T12:06:40+09:00 Subject: Re: NET::HTTP behind a firewall? Yes, eth1 is the public nic. I can not ping anything with the firewall enabled. I can access all the tcp_in ports from external machines. tracert is not working on my workstation right now, it times out to any host on the second hop. My code works properly on my workstations, development servers, and even the production server without the firewall config enabled. Is it possible that NET:HTTP is attempting to use a local port that is lower than NPRIVPORTS allows? Thanks for your help Francis. Thanks, Kris Francis Cianfrocca wrote: > On 10/3/06, Joe Regular wrote: >> >> Joe Regular wrote: > > > > # TCP OUT > # > for tcp_out in $TCP_OUT; do > $IPTABLES -A OUTPUT -o $PUB_IFACE -p tcp -m state --state NEW > --sport $UNPRIVPORTS --dport $tcp_out -j ACCEPT > done > > > Is your routing is configured such that your external servers are > reachable > through eth1? Can you ping anything from this server? Can you telnet to > the > affected external web servers on port 80? Can you traceroute to them > (either > using ICMP or UDP)? Did your code work correctly on a test server that > didn't have this firewall config? What's the output from iptables -L? As > far > as the local (ephemeral) port is concerned, this rule will let anything > out > that is locally bound to any port higher than 1024, which should be ok. -- Posted via http://www.ruby-forum.com/.