Re: Firewall Configuration in Redhat 9.0

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Tue, 2003-10-21 at 07:58, Dominic RIVERA wrote:
> Well, you have a couple of problems:
> 
> You don't want to trust eth0, by trustung eth0 ( your only network card
> ) you are basically disabling the firewall from that interface.
> 
> Dominic Rivera
> (503) 947-7308
> dominic.rivera@xxxxxxxxxxx
> 

Firewall is still doing absolutely nothing, even when I untrust eth0.

> >>> jessem@xxxxxxxxxxxxxxxx 10/20/03 04:00PM >>>
> 
> I've been having some trouble opening and closing ports. Basically, I
> want to close of all ports except 22 for ssh and 3 other ports to do
> some testing with openmosix. No matter what I do though, the ports
> that
> I want open stay closed and the ports that I want closed are open.
> (Mostly)
> 
> Port       State       Service
> 22/tcp     open        ssh
> 25/tcp     open        smtp
> 111/tcp    open        sunrpc
> 139/tcp    open        netbios-ssn
> 505/tcp    open        mailbox-lm
> 631/tcp    open        ipp
> 885/tcp    open        unknown
> 4660/tcp   open        unknown
> 6000/tcp   open        X11
> 9158/tcp   open        unknown
> 10000/tcp  open        snet-sensor-mgmt
> 32768/tcp  open        unknown
> 32769/tcp  open        unknown
> 32770/tcp  open        sometimes-rpc3
> 
> Looks like I don't even have a firewall activated.
> redhat-config-securitylevel is set to medium. If I change it to hight
> the same ports are open. Trusted device is set to my network card
> (eth0)
> nothing is checked except ssh and dhcp. Like I said above, I want a
> couple other ports for open openmosix but, I have not "other ports"
> section using redhat-config-securitylevel.
> 
> Other notes, I have iptables service enabled. It starts at boot. Also,
> I
> have tried to use iptables directly i.e iptables -A INPUT -p tcp ...
> etc. Still nothing.
> 
> Thanks in advance.
> 
> 
> 
> -- 
> Jesse Millan
> CNS Server Team
> Portland State University
> Phone: (503) 725-3285
> Fax:   (503) 725-6487
> GPG key: www.system-calls.com/gpg.php
> 
> I wouldn't be so paranoid if you weren't all out to get me!!
> 
> 
> -- 
> redhat-list mailing list
> unsubscribe mailto:redhat-list-request@xxxxxxxxxx?subject=unsubscribe 
> https://www.redhat.com/mailman/listinfo/redhat-list
-- 
Jesse Millan
CNS Server Team
Portland State University
Phone: (503) 725-3285
Fax:   (503) 725-6487
GPG key: www.system-calls.com/gpg.php

Innovate, don't suffocate. -Ken Fisher


-- 
redhat-list mailing list
unsubscribe mailto:redhat-list-request@xxxxxxxxxx?subject=unsubscribe
https://www.redhat.com/mailman/listinfo/redhat-list

[Index of Archives]     [CentOS]     [Kernel Development]     [PAM]     [Fedora Users]     [Red Hat Development]     [Big List of Linux Books]     [Linux Admin]     [Gimp]     [Asterisk PBX]     [Yosemite News]     [Red Hat Crash Utility]


  Powered by Linux