Re: RedHat 9 stops routing internal packets? Begging for helphere..... please...

From: Pete Nesbitt (pete_at_linux1.ca)
Date: 06/08/04

  • Next message: Marvin Blackburn: "Seeing a newly created lun"
    To: c_elber@SPAMhotmail.com, General Red Hat Linux discussion list <redhat-list@redhat.com>
    Date: Mon, 7 Jun 2004 18:33:07 -0700
    
    

    On June 7, 2004 11:46 am, c_ elber wrote:
    > >What happens if you turn the firwall off. (Service iptables stop). Also
    > >check the traceroute result ??
    > >
    > >VK
    >
    > VK;
    > Thank you so much for the offer of help! When I do service iptables stop
    > then I can no longer ping or traceroute outside addresses from any
    > internal address. I can still ping the router itself but not beyond it.
    > For a traceroute, from a client box, with iptables stopped I get the
    > address of my router and nothing beyond it. From the router itself I can
    > still access the outside which is how I'm emailing.
    >
    > With iptables running I can ping and get a full traced route to a
    > destination such as www.google.com, from a client box, but I can only bring
    > up say a small piece of the page in a browser before it times out.
    > Thanks again,
    > Jo
    >
    > _________________________________________________________________
    > Stop worrying about overloading your inbox - get MSN Hotmail Extra Storage!
    > http://join.msn.click-url.com/go/onm00200362ave/direct/01/

    Hi,
    What are you rules like?
    Here is what it looks like from reading this post:
    Your default rules are deny or reject as opposed to accept.
    You may be missing/misconfig the line to allow established and related. That
    would explain why ping works and traceroute. They are icmp messages, not
    established connections.

    can you post either your rules or else the output of
    'iptables -L' (as Benjamin included).

    -- 
    Pete Nesbitt, rhce
    -- 
    redhat-list mailing list
    unsubscribe mailto:redhat-list-request@redhat.com?subject=unsubscribe
    https://www.redhat.com/mailman/listinfo/redhat-list
    

  • Next message: Marvin Blackburn: "Seeing a newly created lun"

    Relevant Pages

    • nat POSTROUTING chain not traversed during loading?
      ... I've been experiencing some strange behaviour with my netfilter/ ... iptables setup. ... The test is to start a ping before the board is even powered, ... with a static route created when the ath0 interface gets its DHCP ...
      (comp.os.linux.networking)
    • Re: ktorrent bremst Internet aus
      ... PING turing.suse.de 56bytes of data. ... Der Router hat iptables. ... Hier ein Auszug der IPtables vom Router: ... icmp echo-request state NEW ...
      (de.comp.os.unix.apps.kde)
    • Re: Forwarding not work in FC9 but ip_forward is turn on
      ... I installed FC9 on my PC that will work as official proxy / firewall. ... A ping from 192.168.10.20 works toward 192.168.5.254 ... iptables has no rule, in fact I have executed the following ... /sbin/ip route add 192.168.10.1/24 dev eth6 ...
      (Fedora)
    • Forwarding not work in FC9 but ip_forward is turn on
      ... I installed FC9 on my PC that will work as official proxy / firewall. ... A ping from 192.168.10.20 works toward 192.168.5.254 ... 1ms 192.168.5.1: ICMP echo request ... iptables has no rule, in fact I have executed the following ...
      (Fedora)
    • Re: IPMasquerading
      ... I'm using iptables and ipchains is not loaded and does not get loaded at ... >>visa versa) and that the masq server and the masqed machines can ping my ...
      (comp.os.linux.networking)