Find the answer to your Linux question:
Page 2 of 2 FirstFirst 1 2
Results 11 to 15 of 15
You don't have an output rule 5 - do you mean rules 3 & 4? Looks to me like output 3 is your main problem it's blocking an output stream ...
Enjoy an ad free experience by logging in. Not a member yet? Register.
  1. #11
    Just Joined!
    Join Date
    Dec 2007
    Posts
    23

    You don't have an output rule 5 - do you mean rules 3 & 4?

    Looks to me like output 3 is your main problem it's blocking an output stream on localhost.

    Also, my mistake, but switch input rules 6 & 7 (there's no point having an allow after rejecting all).

    Look at the listing you added. Iptables rules basically work down through the relvant chain from top to bottom and implement the first rule that matches the packet.

  2. #12
    Linux Guru
    Join Date
    Sep 2004
    Posts
    1,814
    Quote Originally Posted by billymayday View Post
    You don't have an output rule 5 - do you mean rules 3 & 4?

    Looks to me like output 3 is your main problem it's blocking an output stream on localhost.
    Sorry for my mistake. They are rules 3 and 4
    Code:
    # reject all other traffic from localhost
    iptables -I OUTPUT 3 -j REJECT -s 127.0.0.1 --reject-with icmp-port-unreachable
    
    # reject all other traffic from the management interface NIC
    iptables -I OUTPUT 4 -j REJECT -s 220.232.213.178 --reject-with icmp-port-unreachable
    I can't comment out only rule 3. It complains

    $ sudo /etc/init.d/rc.local start
    Code:
     * Running local boot scripts (/etc/rc.local)                                                                iptables: Index of insertion too big
                                                                                                          [fail]
    Others noted


    B.R.
    satimis

  3. #13
    Just Joined!
    Join Date
    Dec 2007
    Posts
    23
    You probably need to rename insertion 4 to insertion 3

  4. $spacer_open
    $spacer_close
  5. #14
    Linux Guru
    Join Date
    Sep 2004
    Posts
    1,814
    Quote Originally Posted by billymayday View Post
    You probably need to rename insertion 4 to insertion 3
    comment out rule 3 and change insertion 4 to 3 on rule 4. It works. Login squirrelmail w/o problem.


    Thanks.


    satimis

  6. #15
    Just Joined!
    Join Date
    Dec 2007
    Posts
    23
    Whoo hoo

    well done

Page 2 of 2 FirstFirst 1 2

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •