You are not logged in.

#1 2013-08-20 20:03:31

Wolf9466
Member
Registered: 2013-08-17
Posts: 7

Firewall issues

I just set up a firewall with iptables, and now pacman won't update. Does it need a port opened or something? Output is completely unfiltered.

Offline

#2 2013-08-20 20:51:58

brebs
Member
Registered: 2007-04-03
Posts: 3,742

Re: Firewall issues

So tell us how you're filtering INPUT wink

Offline

#3 2013-08-20 21:12:14

Wolf9466
Member
Registered: 2013-08-17
Posts: 7

Re: Firewall issues

Everything dropped except certain ports.

Offline

#4 2013-08-20 21:28:24

brebs
Member
Registered: 2007-04-03
Posts: 3,742

Re: Firewall issues

You're being very coy. So the obvious answer is yes, you'll have to open up the firewall more.

iptables has "-j LOG", so you could take a look yourself at what you're unintentionally dropping.

Offline

#5 2013-08-20 21:52:52

Wolf9466
Member
Registered: 2013-08-17
Posts: 7

Re: Firewall issues

Okay, I didn't think it mattered what exact ports were open, because I would have thought pacman would simply download packages and signature files.

Everything from lo is accepted without question.
Everything entering eth0 is dropped, except for the following ports: 22, 80, 2222, 3333, 3690, 5555, 6666, 7777, 8888, 9999, & 19323.

Offline

#6 2013-08-20 22:31:36

brebs
Member
Registered: 2007-04-03
Posts: 3,742

Re: Firewall issues

Have you excluded this important line?

-A INPUT -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT

Offline

#7 2013-08-20 22:51:43

Wolf9466
Member
Registered: 2013-08-17
Posts: 7

Re: Firewall issues

Yep, thanks.

Offline

#8 2013-08-20 23:32:41

fukawi2
Ex-Administratorino
From: .vic.au
Registered: 2007-09-28
Posts: 6,237
Website

Re: Firewall issues

For future reference, please include all relevant information when asking for assistance... In this instance, posting the output of `iptables -nvL` or `iptables-save` would have identified the issue much faster and easier.

Offline

Board footer

Powered by FluxBB