RE: iptables and samba

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Title: RE: iptables and samba

Hi

This seems to be related to inverse name resolution.
You can try put the client computer name in /etc/hosts and try the conection again.
In some cases samba try to resolv the client computer name, make a DNS query, until the DNS query finish the conection not be establised correctly.

Gratings

David Cardeñosa

-----Mensaje original-----
De: azeem ahmad [mailto:azeem484@xxxxxxxxxxx]
Enviado el: domingo, 23 de mayo de 2004 11:21
Para: netfilter@xxxxxxxxxxxxxxxxxxx
Asunto: iptables and samba


hi
i m using the script below
-------------------------------------------------------------------------------------------------------------------------------------

iptables -F
iptables -t nat -F
iptables -P INPUT DROP
iptables -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 8080 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 22   -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 53   -j ACCEPT
iptables -A INPUT -i eth0 -p udp --dport 53   -j ACCEPT
iptables -A INPUT -i eth0 -p udp --dport 137  -j ACCEPT
iptables -A INPUT -i eth0 -p udp --dport 138  -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 139  -j ACCEPT

iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 8080
#iptables -t nat -A PREROUTING -p udp --dport 80 -j REDIRECT --to-port 8080

iptables -P FORWARD DROP
iptables -A FORWARD -m state --state ESTABLISHED,RELATED -j ACCEPT
iptables -A FORWARD -i eth0 -p tcp --dport 21        -j ACCEPT
iptables -A FORWARD -i eth0 -p tcp --dport 443       -j ACCEPT
iptables -A FORWARD -i eth0 -p tcp --dport 5000      -j ACCEPT
iptables -A FORWARD -i eth0 -p tcp --dport 5001      -j ACCEPT
iptables -A FORWARD -i eth0 -p tcp --dport 5005      -j ACCEPT
iptables -A FORWARD -i eth0 -p tcp --dport 5050      -j ACCEPT
iptables -A FORWARD -i eth0 -p tcp --dport 6660:6670 -j ACCEPT
iptables -A FORWARD -i eth0 -p tcp --dport 7000      -j ACCEPT
iptables -A FORWARD -i eth0 -p tcp --dport 28805     -j ACCEPT
iptables -A FORWARD -i eth0 -p tcp --dport 51215     -j ACCEPT

iptables -t nat -A POSTROUTING -o ppp0 -j MASQUERADE
-------------------------------------------------------------------------------------------------------------------------------------

i have two shares on samba server "Soft and linux" in these shares there are
many folders. whenever i run the above script and then i open the share it
takes atleast 4  minutes to open the share. but it doesnt take time while
browsing inside share.
mean there is a folder on soft share like soft/adobe/acrobat/acrobat6
when i double click on soft it takes atleast 4 minutes but after that when i
click on adobe then acrobat then acrobat6 it takes now time it just brose
them normally. same problem is with the other share named linux.
but if i dont run this script then all shares work fine with no delay

i dont know what is the udp port 80 for but i just saw its traffic on my
network in iptraf so i included it in my script

Regards
Azeem

_________________________________________________________________
Add photos to your e-mail with MSN 8. Get 2 months FREE*.
http://join.msn.com/?page=features/featuredemail


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux