OpenVZ Forum


Home » General » Support » Debian guest iptables config
Debian guest iptables config [message #27205] Tue, 12 February 2008 05:00 Go to previous message
jckdnk111 is currently offline  jckdnk111
Messages: 11
Registered: January 2008
Junior Member
Hi,

I'm attempting to create some very basic firewall rules using shorewall on a Debian guest.

I have set a public, static ip and everything works great while shorewall is stopped. I've configured shorewall to only allow incoming ssh and outgoing dns + http (for installing new software via apt-get).

When I start shorewall I see no errors and my incoming rule works fine. I can ssh into the guest. However, when it comes time to to a dns lookup or visit a website nothing outbound works?

My zones are fw, net, and loc.
My only interface is venet0 mapped to net with my public ip.
My only rules are for incoming ssh, outgoing dns, and outgoing http.
My shorewall policy is set to allow all source's to a destination of net and then drop all other traffic.

I'm confused why I can allow incoming traffic but not outbound traffic ... is this a common problem?

Thanks.
 
Read Message
Read Message
Read Message
Read Message
Previous Topic: ARP? Short network outages on OpenVZ HOST when starting or stopping OVZ nodes (netw bridging)
Next Topic: DNS wont work and cant ping but it works...
Goto Forum:
  


Current Time: Wed Oct 02 23:28:05 GMT 2024

Total time taken to generate the page: 0.05015 seconds