OpenVZ Forum


Home » General » Support » Debian guest iptables config
Debian guest iptables config [message #27205] Tue, 12 February 2008 05:00 Go to next message
jckdnk111 is currently offline  jckdnk111
Messages: 11
Registered: January 2008
Junior Member
Hi,

I'm attempting to create some very basic firewall rules using shorewall on a Debian guest.

I have set a public, static ip and everything works great while shorewall is stopped. I've configured shorewall to only allow incoming ssh and outgoing dns + http (for installing new software via apt-get).

When I start shorewall I see no errors and my incoming rule works fine. I can ssh into the guest. However, when it comes time to to a dns lookup or visit a website nothing outbound works?

My zones are fw, net, and loc.
My only interface is venet0 mapped to net with my public ip.
My only rules are for incoming ssh, outgoing dns, and outgoing http.
My shorewall policy is set to allow all source's to a destination of net and then drop all other traffic.

I'm confused why I can allow incoming traffic but not outbound traffic ... is this a common problem?

Thanks.
Re: Debian guest iptables config [message #27251 is a reply to message #27205] Tue, 12 February 2008 22:21 Go to previous messageGo to next message
jckdnk111 is currently offline  jckdnk111
Messages: 11
Registered: January 2008
Junior Member
now I see that hosts.deny / hosts.allow doesn't work at all on the guests.

Any ideas here?
Re: Debian guest iptables config [message #27381 is a reply to message #27251] Fri, 15 February 2008 21:47 Go to previous messageGo to next message
jckdnk111 is currently offline  jckdnk111
Messages: 11
Registered: January 2008
Junior Member
How does anyone use iptables inside a VE?
Is there a preferred software firewall outside of iptables?

It seems to me that I'm missing some very important concept in the networking model here.

Does anyone read these help requests or do I have to break down and buy the commercial product to get help?
Re: Debian guest iptables config [message #27476 is a reply to message #27205] Mon, 18 February 2008 11:24 Go to previous message
koct9i is currently offline  koct9i
Messages: 51
Registered: February 2008
Member
please post your output for commands
iptables -L -v
iptables -t nat -L -v
inside and outside VE after start shorewall and some outgoing connect try.
Previous Topic: ARP? Short network outages on OpenVZ HOST when starting or stopping OVZ nodes (netw bridging)
Next Topic: DNS wont work and cant ping but it works...
Goto Forum:
  


Current Time: Mon Nov 04 13:13:58 GMT 2024

Total time taken to generate the page: 0.03535 seconds