From: Joe Regular Date: 2006-10-04T12:09:44+09:00 Subject: Re: NET::HTTP behind a firewall? and here is the output of iptables -L... Chain INPUT (policy DROP) target prot opt source destination ACCEPT all -- anywhere anywhere DROP tcp -- anywhere anywhere tcp flags:FIN,SYN,R ST,PSH,ACK,URG/NONE DROP tcp -- anywhere anywhere tcp flags:FIN,SYN/F IN,SYN DROP tcp -- anywhere anywhere tcp flags:SYN,RST/S YN,RST DROP tcp -- anywhere anywhere tcp flags:FIN,RST/F IN,RST DROP tcp -- anywhere anywhere tcp flags:FIN,ACK/F IN DROP tcp -- anywhere anywhere tcp flags:PSH,ACK/P SH DROP tcp -- anywhere anywhere tcp flags:ACK,URG/U RG ACCEPT all -- anywhere anywhere state RELATED,ESTAB LISHED DROP all -- anywhere anywhere state INVALID DROP all -- 10.0.0.0/8 anywhere DROP all -- 172.16.0.0/12 anywhere DROP all -- 127.0.0.0/8 anywhere DROP all -- 255.255.255.255 anywhere DROP all -- anywhere 0.0.0.0 DROP all -- anywhere 255.255.255.255 DROP all -- 224.0.0.0/4 anywhere ACCEPT udp -- anywhere 224.0.0.0/4 ACCEPT igmp -- anywhere 224.0.0.0/4 DROP all -- anywhere 224.0.0.0/4 DROP all -- 240.0.0.0/4 anywhere DROP all -- 0.0.0.0/8 anywhere DROP all -- 169.254.0.0/16 anywhere DROP all -- 192.0.2.0/24 anywhere REJECT tcp -- anywhere anywhere tcp dpt:auth reject -with icmp-port-unreachable REJECT udp -- anywhere anywhere udp dpt:auth reject -with icmp-port-unreachable ACCEPT tcp -- anywhere anywhere state NEW tcp spts: 1024:65535 dpt:ftp-data ACCEPT tcp -- anywhere anywhere state NEW tcp spts: 1024:65535 dpt:ftp ACCEPT tcp -- anywhere anywhere state NEW tcp spts: 1024:65535 dpt:smtp ACCEPT tcp -- anywhere anywhere state NEW tcp spts: 1024:65535 dpt:domain ACCEPT tcp -- anywhere anywhere state NEW tcp spts: 1024:65535 dpt:http ACCEPT tcp -- anywhere anywhere state NEW tcp spts: 1024:65535 dpt:pop3 ACCEPT tcp -- anywhere anywhere state NEW tcp spts: 1024:65535 dpt:imap ACCEPT tcp -- anywhere anywhere state NEW tcp spts: 1024:65535 dpt:https ACCEPT tcp -- anywhere anywhere state NEW tcp spts: 1024:65535 dpt:pop3s ACCEPT tcp -- anywhere anywhere state NEW tcp spts: 1024:65535 dpt:mysql ACCEPT tcp -- anywhere anywhere state NEW tcp spts: 1024:65535 dpt:8443 ACCEPT tcp -- anywhere anywhere state NEW tcp spts: 1024:65535 dpt:10000 ACCEPT tcp -- anywhere anywhere state NEW tcp spts: 1024:65535 dpt:19638 ACCEPT udp -- anywhere anywhere state NEW udp spts: 1024:65535 dpt:domain ACCEPT tcp -- anywhere **mydomain*** state NEW tcp spts: 1024:65535 dpt:ssh ACCEPT icmp -- anywhere **mydomain*** state NEW icmp echo -request ACCEPT udp -- anywhere anywhere udp spt:domain dpt: domain state NEW ACCEPT tcp -- anywhere anywhere tcp spt:domain dpt: domain state NEW Chain FORWARD (policy DROP) target prot opt source destination Chain OUTPUT (policy DROP) target prot opt source destination ACCEPT all -- anywhere anywhere ACCEPT all -- anywhere anywhere state RELATED,ESTAB LISHED DROP all -- anywhere anywhere state INVALID ACCEPT tcp -- anywhere anywhere state NEW tcp spts: 1024:65535 dpt:ftp ACCEPT tcp -- anywhere anywhere state NEW tcp spts: 1024:65535 dpt:ssh ACCEPT tcp -- anywhere anywhere state NEW tcp spts: 1024:65535 dpt:smtp ACCEPT tcp -- anywhere anywhere state NEW tcp spts: 1024:65535 dpt:time ACCEPT tcp -- anywhere anywhere state NEW tcp spts: 1024:65535 dpt:nicname ACCEPT tcp -- anywhere anywhere state NEW tcp spts: 1024:65535 dpt:domain ACCEPT tcp -- anywhere anywhere state NEW tcp spts: 1024:65535 dpt:http ACCEPT tcp -- anywhere anywhere state NEW tcp spts: 1024:65535 dpt:https ACCEPT tcp -- anywhere anywhere state NEW tcp spts: 1024:65535 dpt:55000 ACCEPT udp -- anywhere anywhere state NEW udp spts: 1024:65535 dpt:domain ACCEPT udp -- anywhere anywhere udp spt:domain dpt: domain state NEW ACCEPT tcp -- anywhere anywhere tcp spt:domain dpt: domain state NEW [root@ptp1 ~]# iptables -L Chain INPUT (policy DROP) target prot opt source destination ACCEPT all -- anywhere anywhere DROP tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,PSH,ACK,URG/NONE DROP tcp -- anywhere anywhere tcp flags:FIN,SYN/FIN,SYN DROP tcp -- anywhere anywhere tcp flags:SYN,RST/SYN,RST DROP tcp -- anywhere anywhere tcp flags:FIN,RST/FIN,RST DROP tcp -- anywhere anywhere tcp flags:FIN,ACK/FIN DROP tcp -- anywhere anywhere tcp flags:PSH,ACK/PSH DROP tcp -- anywhere anywhere tcp flags:ACK,URG/URG ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED DROP all -- anywhere anywhere state INVALID DROP all -- 10.0.0.0/8 anywhere DROP all -- 172.16.0.0/12 anywhere DROP all -- 127.0.0.0/8 anywhere DROP all -- 255.255.255.255 anywhere DROP all -- anywhere 0.0.0.0 DROP all -- anywhere 255.255.255.255 DROP all -- 224.0.0.0/4 anywhere ACCEPT udp -- anywhere 224.0.0.0/4 ACCEPT igmp -- anywhere 224.0.0.0/4 DROP all -- anywhere 224.0.0.0/4 DROP all -- 240.0.0.0/4 anywhere DROP all -- 0.0.0.0/8 anywhere DROP all -- 169.254.0.0/16 anywhere DROP all -- 192.0.2.0/24 anywhere REJECT tcp -- anywhere anywhere tcp dpt:auth reject-with icmp-port-unreachable REJECT udp -- anywhere anywhere udp dpt:auth reject-with icmp-port-unreachable ACCEPT tcp -- anywhere anywhere state NEW tcp spts:1024:65535 dpt:ftp-data ACCEPT tcp -- anywhere anywhere state NEW tcp spts:1024:65535 dpt:ftp ACCEPT tcp -- anywhere anywhere state NEW tcp spts:1024:65535 dpt:smtp ACCEPT tcp -- anywhere anywhere state NEW tcp spts:1024:65535 dpt:domain ACCEPT tcp -- anywhere anywhere state NEW tcp spts:1024:65535 dpt:http ACCEPT tcp -- anywhere anywhere state NEW tcp spts:1024:65535 dpt:pop3 ACCEPT tcp -- anywhere anywhere state NEW tcp spts:1024:65535 dpt:imap ACCEPT tcp -- anywhere anywhere state NEW tcp spts:1024:65535 dpt:https ACCEPT tcp -- anywhere anywhere state NEW tcp spts:1024:65535 dpt:pop3s ACCEPT tcp -- anywhere anywhere state NEW tcp spts:1024:65535 dpt:mysql ACCEPT tcp -- anywhere anywhere state NEW tcp spts:1024:65535 dpt:8443 ACCEPT tcp -- anywhere anywhere state NEW tcp spts:1024:65535 dpt:10000 ACCEPT tcp -- anywhere anywhere state NEW tcp spts:1024:65535 dpt:19638 ACCEPT udp -- anywhere anywhere state NEW udp spts:1024:65535 dpt:domain ACCEPT tcp -- anywhere **mydomain** state NEW tcp spts:1024:65535 dpt:ssh ACCEPT icmp -- anywhere **mydomain** state NEW icmp echo-request ACCEPT udp -- anywhere anywhere udp spt:domain dpt:domain state NEW ACCEPT tcp -- anywhere anywhere tcp spt:domain dpt:domain state NEW Chain FORWARD (policy DROP) target prot opt source destination Chain OUTPUT (policy DROP) target prot opt source destination ACCEPT all -- anywhere anywhere ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED DROP all -- anywhere anywhere state INVALID ACCEPT tcp -- anywhere anywhere state NEW tcp spts:1024:65535 dpt:ftp ACCEPT tcp -- anywhere anywhere state NEW tcp spts:1024:65535 dpt:ssh ACCEPT tcp -- anywhere anywhere state NEW tcp spts:1024:65535 dpt:smtp ACCEPT tcp -- anywhere anywhere state NEW tcp spts:1024:65535 dpt:time ACCEPT tcp -- anywhere anywhere state NEW tcp spts:1024:65535 dpt:nicname ACCEPT tcp -- anywhere anywhere state NEW tcp spts:1024:65535 dpt:domain ACCEPT tcp -- anywhere anywhere state NEW tcp spts:1024:65535 dpt:http ACCEPT tcp -- anywhere anywhere state NEW tcp spts:1024:65535 dpt:https ACCEPT tcp -- anywhere anywhere state NEW tcp spts:1024:65535 dpt:55000 ACCEPT udp -- anywhere anywhere state NEW udp spts:1024:65535 dpt:domain ACCEPT udp -- anywhere anywhere udp spt:domain dpt:domain state NEW ACCEPT tcp -- anywhere anywhere tcp spt:domain dpt:domain state NEW Joe Regular wrote: > Yes, eth1 is the public nic. I can not ping anything with the firewall > enabled. I can access all the tcp_in ports from external machines. > tracert is not working on my workstation right now, it times out to any > host on the second hop. > > My code works properly on my workstations, development servers, and even > the production server without the firewall config enabled. > > Is it possible that NET:HTTP is attempting to use a local port that is > lower than NPRIVPORTS allows? > > Thanks for your help Francis. > > Thanks, > Kris > > > > Francis Cianfrocca wrote: >> On 10/3/06, Joe Regular wrote: >>> >>> Joe Regular wrote: >> >> >> >> # TCP OUT >> # >> for tcp_out in $TCP_OUT; do >> $IPTABLES -A OUTPUT -o $PUB_IFACE -p tcp -m state --state NEW >> --sport $UNPRIVPORTS --dport $tcp_out -j ACCEPT >> done >> >> >> Is your routing is configured such that your external servers are >> reachable >> through eth1? Can you ping anything from this server? Can you telnet to >> the >> affected external web servers on port 80? Can you traceroute to them >> (either >> using ICMP or UDP)? Did your code work correctly on a test server that >> didn't have this firewall config? What's the output from iptables -L? As >> far >> as the local (ephemeral) port is concerned, this rule will let anything >> out >> that is locally bound to any port higher than 1024, which should be ok. -- Posted via http://www.ruby-forum.com/.