Bekijk de volledige versie : allow ftp, ssh from wan using olegs 1.9.2.7-7g
I've tried to allow ftp and ssh from WAN, but I haven't any luck.
I followed the steps on http://www.sprayfly.com/wiki/FTP_from_WAN and I've had no luck.
ftp and ssh work fine inside the lan.
Here's my post-firewall:
!/bin/sh
#SSH and FTP access from WAN
iptables -D INPUT -j DROP
iptables -A INPUT -p tcp --dport 21 -j ACCEPT
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
iptables -t nat -A PREROUTING -i vlan1 -p tcp --dport 21 -j DNAT --to-destination $4:21
iptables -t nat -A PREROUTING -i vlan1 -p tcp --dport 22 -j DNAT --to-destination $4:22
iptables -A INPUT -j DROP
you also need a rule for port 20. ftp uses both port 20 and 21
As minimum, two lines with PREROUTING are nonsense. Remove them.
Check out which rules do you have currently with iptables -L
Correctness of the iptables -D INPUT -j DROP statement depends on the setting in the web-IF of how to log the firewall activity.
iptable -L :
Chain INPUT (policy ACCEPT)
target prot opt source destination
DROP all -- anywhere anywhere state INVALID
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT all -- anywhere anywhere state NEW
ACCEPT all -- anywhere anywhere state NEW
DROP all -- anywhere anywhere
Chain FORWARD (policy ACCEPT)
target prot opt source destination
If I change the logged packet types in the Web-if, what should I be looking for?
At the moment from the iptables -L output it seems that your post-firewall is not executed at all.
If I change the logged packet types in the Web-if, what should I be looking for?
If you setup to log e.g. dropped packets, the last line will be:
iptables -D INPUT -j logdrop
So, the iptables -D INPUT -j DROP will do nothing, because there is no such rule.
Last line of output: DROP all -- anywhere anywhere suggests that it is set up correctly.
I don't know why ACCEPT all -- anywhere anywhere state NEW is repeated twice.
BTW!!!
The first line of the file should be not !/bin/sh, but #!/bin/sh !!!
there is a # at the start of the script. I missed it when I did the copy/paste.
I double checked everything, and the script is executable. I'm at a loss here.
is there anything in the web interface that needs to be set/unset that wasn't mentioned in the guide?
I double checked everything, and the script is executable. I'm at a loss here.
However it is not executed. If you run post-firewall manually, does the output of iptables -L change?
One more idea how to ascertain the execution of post-firewall: add the following line:
logger "post-firewall started."
and check the log-file.
I hope you have not used windows editors to create this file? One more possible reason of non-execution are wrong end-of-line characters.
ok, I haven't had time to play with this for a few days, but I got back at it tonight. I was able to get it to execute the script finally, but I still can't get in from the outside.
Here's what I now get from iptables -L:
Chain INPUT (policy ACCEPT)
target prot opt source destination
logdrop all -- anywhere anywhere state INVALID
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT all -- anywhere anywhere state NEW
ACCEPT all -- anywhere anywhere state NEW
logdrop all -- anywhere anywhere
ACCEPT tcp -- anywhere anywhere tcp dpt:ftp-data
ACCEPT tcp -- anywhere anywhere tcp dpt:ftp
ACCEPT tcp -- anywhere anywhere tcp dpt:24
DROP all -- anywhere anywhere
Chain FORWARD (policy ACCEPT)
target prot opt source destination
ACCEPT all -- anywhere anywhere
logdrop all -- anywhere anywhere state INVALID
TCPMSS tcp -- anywhere anywhere tcp flags:SYN,RST/SYN tcpmss match 1453:65535TCPMSS set 1452
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
logdrop all -- anywhere anywhere
logdrop all -- anywhere anywhere
ACCEPT all -- anywhere anywhere ctstate DNAT
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
Chain MACS (0 references)
target prot opt source destination
Chain SECURITY (0 references)
target prot opt source destination
RETURN tcp -- anywhere anywhere tcp flags:SYN,RST,ACK/SYN limit: avg 1/sec burst 5
RETURN tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,ACK/RST limit: avg 1/sec burst 5
RETURN udp -- anywhere anywhere limit: avg 5/sec burst 5
RETURN icmp -- anywhere anywhere limit: avg 5/sec burst 5
logdrop all -- anywhere anywhere
Chain logaccept (0 references)
target prot opt source destination
LOG all -- anywhere anywhere state NEW LOG level warning tcp-sequence tcp-options ip-options prefix `ACCEPT '
ACCEPT all -- anywhere anywhere
Chain logdrop (6 references)
target prot opt source destination
LOG all -- anywhere anywhere state NEW LOG level warning tcp-sequence tcp-options ip-options prefix `DROP '
DROP all -- anywhere anywhere
I can see that ftp is set to accept, and that ssh is there as well and on port 24.
And I'm not using windows. I'm on ubuntu for my desktop.
thanks!
You don't go beyond:
logdrop all -- anywhere anywhere
I explained you in this topic above why.