Hozzászólások
-
SzerzőBejegyzés
-
Hoppá el csesztem,végig zongoráztam amit le irtál elsö sor ki töröl semi változás.
Kicsit ideges letem,grafikus program kezelö shorewall töröltem.Hát ezt el kapkodtam, akkor telepitsem
ujra.Hoppá el csesztem,végig zongoráztam amit le irtál elsö sor ki töröl semi változás.
Kicsit ideges letem,grafikus program kezelö shorewall töröltem.Hát ezt el kapkodtam, akkor telepitsem
ujra.Elnézést a durva szövegért,csak meg ijedtem hogy tönkre teszek valamit.De mint irtam kezdö vagyok,
kb 1.5 éve van csak gépem.Iptables volt üres is a shorewall clear parancs után,de ki kapcs ujra be kapcs
ujra van iptables enyi biztos. Akkor brobálkozom v3ctor le írásával,eredményt jelzem.
Elöre is köszönöm hogy velem kinlodtok.Elnézést a durva szövegért,csak meg ijedtem hogy tönkre teszek valamit.De mint irtam kezdö vagyok,
kb 1.5 éve van csak gépem.Iptables volt üres is a shorewall clear parancs után,de ki kapcs ujra be kapcs
ujra van iptables enyi biztos. Akkor brobálkozom v3ctor le írásával,eredményt jelzem.
Elöre is köszönöm hogy velem kinlodtok.A ping 74.125.67.100-ra a válasz ne szivasatok nem tudtam le állitani. Másodpercenként küldte 3 percig
hagytam, nem tudtam mást ki léptem.A ping 74.125.67.100-ra a válasz ne szivasatok nem tudtam le állitani. Másodpercenként küldte 3 percig
hagytam, nem tudtam mást ki léptem.Bocsi de fázis késésben vagyok,mint irtam egyik rendszer ki kapcs másik be kapcs oda visza játszok.
De az iptables -L-re a válasz
[root@localhost blackpanther]# iptables -L
Chain INPUT (policy DROP)
target prot opt source destination
ACCEPT all — anywhere anywhere
ppp_in all — anywhere anywhere
eth0_in all — anywhere anywhere
Reject all — anywhere anywhere
LOG all — anywhere anywhere LOG level info prefix `Shorewall:INPUT:REJECT:’
reject all — anywhere anywhereChain FORWARD (policy DROP)
target prot opt source destination
ppp_fwd all — anywhere anywhere
eth0_fwd all — anywhere anywhere
Reject all — anywhere anywhere
LOG all — anywhere anywhere LOG level info prefix `Shorewall:FORWARD:REJECT:’
reject all — anywhere anywhereChain OUTPUT (policy DROP)
target prot opt source destination
ACCEPT all — anywhere anywhere
fw2net all — anywhere anywhere policy match dir out pol none
fw2loc all — anywhere anywhere policy match dir out pol none
Reject all — anywhere anywhere
LOG all — anywhere anywhere LOG level info prefix `Shorewall:OUTPUT:REJECT:’
reject all — anywhere anywhereChain AllowICMPs (2 references)
target prot opt source destination
ACCEPT icmp — anywhere anywhere icmp fragmentation-needed
ACCEPT icmp — anywhere anywhere icmp time-exceededChain Drop (1 references)
target prot opt source destination
RejectAuth all — anywhere anywhere
dropBcast all — anywhere anywhere
AllowICMPs icmp — anywhere anywhere
dropInvalid all — anywhere anywhere
DropSMB all — anywhere anywhere
DropUPnP all — anywhere anywhere
dropNotSyn tcp — anywhere anywhere
DropDNSrep all — anywhere anywhereChain DropDNSrep (2 references)
target prot opt source destination
DROP udp — anywhere anywhere udp spt:domainChain DropSMB (1 references)
target prot opt source destination
DROP udp — anywhere anywhere udp dpt:135
DROP udp — anywhere anywhere udp dpts:netbios-ns:netbios-ssn
DROP udp — anywhere anywhere udp dpt:microsoft-ds
DROP tcp — anywhere anywhere tcp dpt:135
DROP tcp — anywhere anywhere tcp dpt:netbios-ssn
DROP tcp — anywhere anywhere tcp dpt:microsoft-dsChain DropUPnP (2 references)
target prot opt source destination
DROP udp — anywhere anywhere udp dpt:1900Chain Reject (4 references)
target prot opt source destination
RejectAuth all — anywhere anywhere
dropBcast all — anywhere anywhere
AllowICMPs icmp — anywhere anywhere
dropInvalid all — anywhere anywhere
RejectSMB all — anywhere anywhere
DropUPnP all — anywhere anywhere
dropNotSyn tcp — anywhere anywhere
DropDNSrep all — anywhere anywhereChain RejectAuth (2 references)
target prot opt source destination
reject tcp — anywhere anywhere tcp dpt:authChain RejectSMB (1 references)
target prot opt source destination
reject udp — anywhere anywhere udp dpt:135
reject udp — anywhere anywhere udp dpts:netbios-ns:netbios-ssn
reject udp — anywhere anywhere udp dpt:microsoft-ds
reject tcp — anywhere anywhere tcp dpt:135
reject tcp — anywhere anywhere tcp dpt:netbios-ssn
reject tcp — anywhere anywhere tcp dpt:microsoft-dsChain all2all (1 references)
target prot opt source destination
ACCEPT all — anywhere anywhere state RELATED,ESTABLISHED
Reject all — anywhere anywhere
LOG all — anywhere anywhere LOG level info prefix `Shorewall:all2all:REJECT:’
reject all — anywhere anywhereChain dropBcast (2 references)
target prot opt source destination
DROP all — anywhere anywhere PKTTYPE = broadcast
DROP all — anywhere anywhere PKTTYPE = multicastChain dropInvalid (2 references)
target prot opt source destination
DROP all — anywhere anywhere state INVALIDChain dropNotSyn (2 references)
target prot opt source destination
DROP tcp — anywhere anywhere tcp flags:!FIN,SYN,RST,ACK/SYNChain dynamic (4 references)
target prot opt source destinationChain eth0_fwd (1 references)
target prot opt source destination
dynamic all — anywhere anywhere state INVALID,NEW
loc2net all — anywhere anywhere policy match dir out pol noneChain eth0_in (1 references)
target prot opt source destination
dynamic all — anywhere anywhere state INVALID,NEW
loc2fw all — anywhere anywhere policy match dir in pol noneChain fw2loc (1 references)
target prot opt source destination
ACCEPT all — anywhere anywhere state RELATED,ESTABLISHED
ACCEPT all — anywhere anywhereChain fw2net (1 references)
target prot opt source destination
ACCEPT all — anywhere anywhere state RELATED,ESTABLISHED
ACCEPT all — anywhere anywhereChain loc2fw (1 references)
target prot opt source destination
ACCEPT all — anywhere anywhere state RELATED,ESTABLISHED
ACCEPT tcp — anywhere anywhere multiport dports ftp-data,ftp,ssh
ACCEPT icmp — anywhere anywhere icmp echo-request
all2all all — anywhere anywhereChain loc2net (1 references)
target prot opt source destination
ACCEPT all — anywhere anywhere state RELATED,ESTABLISHED
ACCEPT all — anywhere anywhereChain net2all (2 references)
target prot opt source destination
ACCEPT all — anywhere anywhere state RELATED,ESTABLISHED
Drop all — anywhere anywhere
LOG all — anywhere anywhere LOG level info prefix `Shorewall:net2all:DROP:’
DROP all — anywhere anywhereChain net2fw (1 references)
target prot opt source destination
ACCEPT all — anywhere anywhere state RELATED,ESTABLISHED
ACCEPT tcp — anywhere anywhere multiport dports ftp-data,ftp,ssh
ACCEPT icmp — anywhere anywhere icmp echo-request
net2all all — anywhere anywhereChain ppp_fwd (1 references)
target prot opt source destination
dynamic all — anywhere anywhere state INVALID,NEW
net2all all — anywhere anywhere policy match dir out pol noneChain ppp_in (1 references)
target prot opt source destination
dynamic all — anywhere anywhere state INVALID,NEW
net2fw all — anywhere anywhere policy match dir in pol noneChain reject (11 references)
target prot opt source destination
DROP all — anywhere anywhere PKTTYPE = broadcast
DROP all — anywhere anywhere PKTTYPE = multicast
DROP all — 255.255.255.255 anywhere
DROP all — 224.0.0.0/4 anywhere
REJECT tcp — anywhere anywhere reject-with tcp-reset
REJECT udp — anywhere anywhere reject-with icmp-port-unreachable
REJECT icmp — anywhere anywhere reject-with icmp-host-unreachable
REJECT all — anywhere anywhere reject-with icmp-host-prohibitedChain shorewall (0 references)
target prot opt source destinationChain smurfs (0 references)
target prot opt source destination
LOG all — 255.255.255.255 anywhere LOG level info prefix `Shorewall:smurfs:DROP:’
DROP all — 255.255.255.255 anywhere
LOG all — 224.0.0.0/4 anywhere LOG level info prefix `Shorewall:smurfs:DROP:’
DROP all — 224.0.0.0/4 anywhere
[root@localhost blackpanther]#
a pinget probállom mindjárt jövök viszaBocsi de fázis késésben vagyok,mint irtam egyik rendszer ki kapcs másik be kapcs oda visza játszok.
De az iptables -L-re a válasz
[root@localhost blackpanther]# iptables -L
Chain INPUT (policy DROP)
target prot opt source destination
ACCEPT all — anywhere anywhere
ppp_in all — anywhere anywhere
eth0_in all — anywhere anywhere
Reject all — anywhere anywhere
LOG all — anywhere anywhere LOG level info prefix `Shorewall:INPUT:REJECT:’
reject all — anywhere anywhereChain FORWARD (policy DROP)
target prot opt source destination
ppp_fwd all — anywhere anywhere
eth0_fwd all — anywhere anywhere
Reject all — anywhere anywhere
LOG all — anywhere anywhere LOG level info prefix `Shorewall:FORWARD:REJECT:’
reject all — anywhere anywhereChain OUTPUT (policy DROP)
target prot opt source destination
ACCEPT all — anywhere anywhere
fw2net all — anywhere anywhere policy match dir out pol none
fw2loc all — anywhere anywhere policy match dir out pol none
Reject all — anywhere anywhere
LOG all — anywhere anywhere LOG level info prefix `Shorewall:OUTPUT:REJECT:’
reject all — anywhere anywhereChain AllowICMPs (2 references)
target prot opt source destination
ACCEPT icmp — anywhere anywhere icmp fragmentation-needed
ACCEPT icmp — anywhere anywhere icmp time-exceededChain Drop (1 references)
target prot opt source destination
RejectAuth all — anywhere anywhere
dropBcast all — anywhere anywhere
AllowICMPs icmp — anywhere anywhere
dropInvalid all — anywhere anywhere
DropSMB all — anywhere anywhere
DropUPnP all — anywhere anywhere
dropNotSyn tcp — anywhere anywhere
DropDNSrep all — anywhere anywhereChain DropDNSrep (2 references)
target prot opt source destination
DROP udp — anywhere anywhere udp spt:domainChain DropSMB (1 references)
target prot opt source destination
DROP udp — anywhere anywhere udp dpt:135
DROP udp — anywhere anywhere udp dpts:netbios-ns:netbios-ssn
DROP udp — anywhere anywhere udp dpt:microsoft-ds
DROP tcp — anywhere anywhere tcp dpt:135
DROP tcp — anywhere anywhere tcp dpt:netbios-ssn
DROP tcp — anywhere anywhere tcp dpt:microsoft-dsChain DropUPnP (2 references)
target prot opt source destination
DROP udp — anywhere anywhere udp dpt:1900Chain Reject (4 references)
target prot opt source destination
RejectAuth all — anywhere anywhere
dropBcast all — anywhere anywhere
AllowICMPs icmp — anywhere anywhere
dropInvalid all — anywhere anywhere
RejectSMB all — anywhere anywhere
DropUPnP all — anywhere anywhere
dropNotSyn tcp — anywhere anywhere
DropDNSrep all — anywhere anywhereChain RejectAuth (2 references)
target prot opt source destination
reject tcp — anywhere anywhere tcp dpt:authChain RejectSMB (1 references)
target prot opt source destination
reject udp — anywhere anywhere udp dpt:135
reject udp — anywhere anywhere udp dpts:netbios-ns:netbios-ssn
reject udp — anywhere anywhere udp dpt:microsoft-ds
reject tcp — anywhere anywhere tcp dpt:135
reject tcp — anywhere anywhere tcp dpt:netbios-ssn
reject tcp — anywhere anywhere tcp dpt:microsoft-dsChain all2all (1 references)
target prot opt source destination
ACCEPT all — anywhere anywhere state RELATED,ESTABLISHED
Reject all — anywhere anywhere
LOG all — anywhere anywhere LOG level info prefix `Shorewall:all2all:REJECT:’
reject all — anywhere anywhereChain dropBcast (2 references)
target prot opt source destination
DROP all — anywhere anywhere PKTTYPE = broadcast
DROP all — anywhere anywhere PKTTYPE = multicastChain dropInvalid (2 references)
target prot opt source destination
DROP all — anywhere anywhere state INVALIDChain dropNotSyn (2 references)
target prot opt source destination
DROP tcp — anywhere anywhere tcp flags:!FIN,SYN,RST,ACK/SYNChain dynamic (4 references)
target prot opt source destinationChain eth0_fwd (1 references)
target prot opt source destination
dynamic all — anywhere anywhere state INVALID,NEW
loc2net all — anywhere anywhere policy match dir out pol noneChain eth0_in (1 references)
target prot opt source destination
dynamic all — anywhere anywhere state INVALID,NEW
loc2fw all — anywhere anywhere policy match dir in pol noneChain fw2loc (1 references)
target prot opt source destination
ACCEPT all — anywhere anywhere state RELATED,ESTABLISHED
ACCEPT all — anywhere anywhereChain fw2net (1 references)
target prot opt source destination
ACCEPT all — anywhere anywhere state RELATED,ESTABLISHED
ACCEPT all — anywhere anywhereChain loc2fw (1 references)
target prot opt source destination
ACCEPT all — anywhere anywhere state RELATED,ESTABLISHED
ACCEPT tcp — anywhere anywhere multiport dports ftp-data,ftp,ssh
ACCEPT icmp — anywhere anywhere icmp echo-request
all2all all — anywhere anywhereChain loc2net (1 references)
target prot opt source destination
ACCEPT all — anywhere anywhere state RELATED,ESTABLISHED
ACCEPT all — anywhere anywhereChain net2all (2 references)
target prot opt source destination
ACCEPT all — anywhere anywhere state RELATED,ESTABLISHED
Drop all — anywhere anywhere
LOG all — anywhere anywhere LOG level info prefix `Shorewall:net2all:DROP:’
DROP all — anywhere anywhereChain net2fw (1 references)
target prot opt source destination
ACCEPT all — anywhere anywhere state RELATED,ESTABLISHED
ACCEPT tcp — anywhere anywhere multiport dports ftp-data,ftp,ssh
ACCEPT icmp — anywhere anywhere icmp echo-request
net2all all — anywhere anywhereChain ppp_fwd (1 references)
target prot opt source destination
dynamic all — anywhere anywhere state INVALID,NEW
net2all all — anywhere anywhere policy match dir out pol noneChain ppp_in (1 references)
target prot opt source destination
dynamic all — anywhere anywhere state INVALID,NEW
net2fw all — anywhere anywhere policy match dir in pol noneChain reject (11 references)
target prot opt source destination
DROP all — anywhere anywhere PKTTYPE = broadcast
DROP all — anywhere anywhere PKTTYPE = multicast
DROP all — 255.255.255.255 anywhere
DROP all — 224.0.0.0/4 anywhere
REJECT tcp — anywhere anywhere reject-with tcp-reset
REJECT udp — anywhere anywhere reject-with icmp-port-unreachable
REJECT icmp — anywhere anywhere reject-with icmp-host-unreachable
REJECT all — anywhere anywhere reject-with icmp-host-prohibitedChain shorewall (0 references)
target prot opt source destinationChain smurfs (0 references)
target prot opt source destination
LOG all — 255.255.255.255 anywhere LOG level info prefix `Shorewall:smurfs:DROP:’
DROP all — 255.255.255.255 anywhere
LOG all — 224.0.0.0/4 anywhere LOG level info prefix `Shorewall:smurfs:DROP:’
DROP all — 224.0.0.0/4 anywhere
[root@localhost blackpanther]#
a pinget probállom mindjárt jövök viszaÜdv,én is föl adtam az este.De vissza térve a problémára idegesitet tüzfal.Grafikusan már ki kapcsoltam
a legelsö dolog amire gondoltam,de felül irta grafikusan nem lehet ki kapcsolni. De el tértem a tárgytol,
még egyszer ki adtam a parancsokat kicsit meg keverve az eredmény.
[root@localhost blackpanther]# shorewall clear
Loading /usr/share/shorewall/functions…
Processing /etc/shorewall/params …
Processing /etc/shorewall/shorewall.conf…
Loading Modules…
Clearing Shorewall…Processing /etc/shorewall/stop …
WARNING: DISABLE_IPV6=Yes in shorewall.conf but this system does not appear to have ip6tables
IP Forwarding Enabled
Processing /etc/shorewall/stopped …
done.
[root@localhost blackpanther]# ping google.com
ping: unknown host google.com
[root@localhost blackpanther]# iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destinationChain FORWARD (policy ACCEPT)
target prot opt source destinationChain OUTPUT (policy ACCEPT)
target prot opt source destination
nem tudom segit e valamit
Azt nem irtam hogy Live CD változat, hátha van valami másik program ami befolyásolja a rendszert.
Az iptables -L folyamatban mindjárt másolom.Üdv,én is föl adtam az este.De vissza térve a problémára idegesitet tüzfal.Grafikusan már ki kapcsoltam
a legelsö dolog amire gondoltam,de felül irta grafikusan nem lehet ki kapcsolni. De el tértem a tárgytol,
még egyszer ki adtam a parancsokat kicsit meg keverve az eredmény.
[root@localhost blackpanther]# shorewall clear
Loading /usr/share/shorewall/functions…
Processing /etc/shorewall/params …
Processing /etc/shorewall/shorewall.conf…
Loading Modules…
Clearing Shorewall…Processing /etc/shorewall/stop …
WARNING: DISABLE_IPV6=Yes in shorewall.conf but this system does not appear to have ip6tables
IP Forwarding Enabled
Processing /etc/shorewall/stopped …
done.
[root@localhost blackpanther]# ping google.com
ping: unknown host google.com
[root@localhost blackpanther]# iptables -L
Chain INPUT (policy ACCEPT)
target prot opt source destinationChain FORWARD (policy ACCEPT)
target prot opt source destinationChain OUTPUT (policy ACCEPT)
target prot opt source destination
nem tudom segit e valamit
Azt nem irtam hogy Live CD változat, hátha van valami másik program ami befolyásolja a rendszert.
Az iptables -L folyamatban mindjárt másolom. -
SzerzőBejegyzés
legutóbbi hsz