PDA

Bekijk de volledige versie : allow ftp, ssh from wan using olegs 1.9.2.7-7g



oggie
07-11-2007, 01:00
I've tried to allow ftp and ssh from WAN, but I haven't any luck.

I followed the steps on http://www.sprayfly.com/wiki/FTP_from_WAN and I've had no luck.

ftp and ssh work fine inside the lan.

Here's my post-firewall:
!/bin/sh
#SSH and FTP access from WAN
iptables -D INPUT -j DROP
iptables -A INPUT -p tcp --dport 21 -j ACCEPT
iptables -A INPUT -p tcp --dport 22 -j ACCEPT
iptables -t nat -A PREROUTING -i vlan1 -p tcp --dport 21 -j DNAT --to-destination $4:21
iptables -t nat -A PREROUTING -i vlan1 -p tcp --dport 22 -j DNAT --to-destination $4:22
iptables -A INPUT -j DROP

avberk
07-11-2007, 21:05
you also need a rule for port 20. ftp uses both port 20 and 21

al37919
07-11-2007, 21:10
As minimum, two lines with PREROUTING are nonsense. Remove them.

Check out which rules do you have currently with iptables -L

Correctness of the iptables -D INPUT -j DROP statement depends on the setting in the web-IF of how to log the firewall activity.

oggie
08-11-2007, 02:38
iptable -L :
Chain INPUT (policy ACCEPT)
target prot opt source destination
DROP all -- anywhere anywhere state INVALID
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT all -- anywhere anywhere state NEW
ACCEPT all -- anywhere anywhere state NEW
DROP all -- anywhere anywhere

Chain FORWARD (policy ACCEPT)
target prot opt source destination

If I change the logged packet types in the Web-if, what should I be looking for?

al37919
08-11-2007, 13:04
At the moment from the iptables -L output it seems that your post-firewall is not executed at all.


If I change the logged packet types in the Web-if, what should I be looking for?

If you setup to log e.g. dropped packets, the last line will be:
iptables -D INPUT -j logdrop
So, the iptables -D INPUT -j DROP will do nothing, because there is no such rule.

Last line of output: DROP all -- anywhere anywhere suggests that it is set up correctly.

I don't know why ACCEPT all -- anywhere anywhere state NEW is repeated twice.

BTW!!!
The first line of the file should be not !/bin/sh, but #!/bin/sh !!!

oggie
09-11-2007, 15:20
there is a # at the start of the script. I missed it when I did the copy/paste.

I double checked everything, and the script is executable. I'm at a loss here.

is there anything in the web interface that needs to be set/unset that wasn't mentioned in the guide?

al37919
09-11-2007, 16:30
I double checked everything, and the script is executable. I'm at a loss here.

However it is not executed. If you run post-firewall manually, does the output of iptables -L change?

One more idea how to ascertain the execution of post-firewall: add the following line:
logger "post-firewall started."
and check the log-file.

I hope you have not used windows editors to create this file? One more possible reason of non-execution are wrong end-of-line characters.

oggie
15-11-2007, 03:02
ok, I haven't had time to play with this for a few days, but I got back at it tonight. I was able to get it to execute the script finally, but I still can't get in from the outside.

Here's what I now get from iptables -L:


Chain INPUT (policy ACCEPT)
target prot opt source destination
logdrop all -- anywhere anywhere state INVALID
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
ACCEPT all -- anywhere anywhere state NEW
ACCEPT all -- anywhere anywhere state NEW
logdrop all -- anywhere anywhere
ACCEPT tcp -- anywhere anywhere tcp dpt:ftp-data
ACCEPT tcp -- anywhere anywhere tcp dpt:ftp
ACCEPT tcp -- anywhere anywhere tcp dpt:24
DROP all -- anywhere anywhere

Chain FORWARD (policy ACCEPT)
target prot opt source destination
ACCEPT all -- anywhere anywhere
logdrop all -- anywhere anywhere state INVALID
TCPMSS tcp -- anywhere anywhere tcp flags:SYN,RST/SYN tcpmss match 1453:65535TCPMSS set 1452
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
logdrop all -- anywhere anywhere
logdrop all -- anywhere anywhere
ACCEPT all -- anywhere anywhere ctstate DNAT

Chain OUTPUT (policy ACCEPT)
target prot opt source destination

Chain MACS (0 references)
target prot opt source destination

Chain SECURITY (0 references)
target prot opt source destination
RETURN tcp -- anywhere anywhere tcp flags:SYN,RST,ACK/SYN limit: avg 1/sec burst 5
RETURN tcp -- anywhere anywhere tcp flags:FIN,SYN,RST,ACK/RST limit: avg 1/sec burst 5
RETURN udp -- anywhere anywhere limit: avg 5/sec burst 5
RETURN icmp -- anywhere anywhere limit: avg 5/sec burst 5
logdrop all -- anywhere anywhere

Chain logaccept (0 references)
target prot opt source destination
LOG all -- anywhere anywhere state NEW LOG level warning tcp-sequence tcp-options ip-options prefix `ACCEPT '
ACCEPT all -- anywhere anywhere

Chain logdrop (6 references)
target prot opt source destination
LOG all -- anywhere anywhere state NEW LOG level warning tcp-sequence tcp-options ip-options prefix `DROP '
DROP all -- anywhere anywhere

I can see that ftp is set to accept, and that ssh is there as well and on port 24.

And I'm not using windows. I'm on ubuntu for my desktop.

thanks!

al37919
15-11-2007, 08:31
You don't go beyond:
logdrop all -- anywhere anywhere
I explained you in this topic above why.