/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
I have been using ipchains for a month, only this
morning none of the user could send email. I get the
following error in my log:
Feb 24 02:45:23 linux kernel: Packet log: input DENY
ppp0 PROTO=6 205.180.183.3:1202 209.69.204.143:113 L=60
S=0x00 I=90 F=0x4000 T=48
Feb 24 02:45:26 linux kernel: Packet log: input DENY
ppp0 PROTO=6 205.180.183.3:1202 209.69.204.143:113 L=60
S=0x00 I=203 F=0x4000 T=48
Feb 24 02:45:32 linux kernel: Packet log: input DENY
ppp0 PROTO=6 205.180.183.3:1202 209.69.204.143:113 L=60
S=0x00 I=295 F=0x4000 T=48
Feb 24 02:45:44 linux kernel: Packet log: input DENY
ppp0 PROTO=6 205.180.183.3:1202 209.69.204.143:113 L=60
S=0x00 I=421 F=0x4000 T=48
Feb 24 02:46:55 linux kernel: Packet log: input DENY
ppp0 PROTO=6 209.69.206.251:32133 209.69.204.143:113
L=44 S=0x00 I=29443 F=0x0000 T=58
Feb 24 02:47:02 linux kernel: Packet log: input DENY
ppp0 PROTO=6 209.69.206.251:32133 209.69.204.143:113
L=44 S=0x00 I=29488 F=0x0000 T=58
Feb 24 02:47:25 linux kernel: Packet log: input DENY
ppp0 PROTO=6 209.69.206.251:32133 209.69.204.143:113
L=44 S=0x00 I=29848 F=0x0000 T=58
Here is my rulesets with ipchains (somewhat trimmed):
# flush residual BS
/sbin/ipchains -F
# I saw this somewhere ...let's try it ...
/sbin/depmod -a
# Load modules
/sbin/modprobe ip_masq_ftp
/sbin/modprobe ip_masq_raudio
/sbin/modprobe ip_masq_vdolive
# default is to deny
/sbin/ipchains -P forward DENY
# Attempt to optimize throughput
/sbin/ipchains -A output -p tcp -d 0.0.0.0/0 telnet -t
0x01 0x10
/sbin/ipchains -A output -p tcp -d 0.0.0.0/0 ftp -t
0x01 0x10
/sbin/ipchains -A output -p tcp -s 0.0.0.0/0 ftp-data
-t 0x01 0x08
# here we go ...........
/sbin/ipchains -A output -d 199.95.207.0/24 -j REJECT
/sbin/ipchains -A output -d 199.95.208.0/24 -j REJECT
/sbin/ipchains -A output -d 209.67.38.62/24 -j REJECT
# /sbin/ipchains -A output -d 192.147.174.126:80 -j
DENY
/sbin/ipchains -A forward -j MASQ -s 10.1.1.1/8 -d
0.0.0.0/0
/sbin/ipchains -A forward -j MASQ -s 10.1.1.2/24 -d
0.0.0.0/0
/sbin/ipchains -l -A forward -j MASQ -s 10.1.1.3/24 -d
0.0.0.0/0
/sbin/ipchains -A forward -j MASQ -s 10.1.1.5/8 -d
0.0.0.0/0
/sbin/ipchains -A forward -j MASQ -s 10.1.1.6/24 -d
0.0.0.0/0
# Whack unwanted visitors
/sbin/ipchains -P input ACCEPT
/sbin/ipchains -A input -l -i ppp0 -p tcp --dport
31780:31790 -j DENY
/sbin/ipchains -A input -l -i ppp0 -p udp --dport
31780:31790 -j DENY
/sbin/ipchains -A input -l -i ppp0 -p tcp --dport
21:1024 -j DENY
/sbin/ipchains -A input -l -i ppp0 -p tcp --dport 113
-j ACCEPT
/sbin/ipchains -A input -l -i ppp0 -p udp --dport 113
-j ACCEPT
/sbin/ipchains -A input -l -i ppp0 -p tcp --dport 6000
-j DENY
/sbin/ipchains -A input -l -i ppp0 -p udp --dport
21:1024 -j DENY
/sbin/ipchains -A input -l -i ppp0 -p udp --dport 6000
-j DENY
I added the "ACCEPT" lines above to try and allow the
mail to get thru, but it didn't seem to help. Actually,
everything was working fine since I got it set up, and
it started acting up this morning. Any help would be
appreciated.
--
Tom
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.