Re: B3 inaccessible with limited functionality
Posted: 11 Oct 2014, 17:55
Maby you should look into the firewall rules. It should not increas the bot time but it can defenitly make it impossible to ssh into the bubba.
Bubba community forum
https://forum.excito.org/
Code: Select all
#vi /mnt/etc/firewall.conf
- firewall.conf 1/47 2%
# Generated by iptables-save v1.4.8 on Thu Oct 2 09:37:25 2014
*filter
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [0:0]
-A INPUT -p tcp -m tcp --tcp-flags SYN,ACK SYN,ACK -m state --state NEW -j REJECT --reject-with tcp-reset
-A INPUT -p tcp -m tcp ! --tcp-flags FIN,SYN,RST,ACK SYN -m state --state NEW -j DROP
-A INPUT -i eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i br0 -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -i eth0 -p icmp -m icmp --icmp-type 11 -j ACCEPT
-A INPUT -i eth0 -p icmp -m icmp --icmp-type 8 -j ACCEPT
-A INPUT -p icmp -m icmp --icmp-type 3/4 -j ACCEPT
-A INPUT -i tap0 -j ACCEPT
-A INPUT -i br0 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 80 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 443 -j ACCEPT
-A INPUT -i eth0 -p udp -m udp --dport 1194 -j ACCEPT
-A FORWARD -i br0 -j ACCEPT
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -p icmp -m icmp --icmp-type 3/4 -j ACCEPT
-A FORWARD -d 10.3.2.14/32 -p udp -m udp --dport 1194 -j ACCEPT
-A FORWARD -d 10.3.2.14/32 -p tcp -m tcp --dport 465 -j ACCEPT
-A FORWARD -d 10.3.2.14/32 -p udp -m udp --dport 465 -j ACCEPT
-A FORWARD -d 10.3.2.14/32 -p udp -m udp --dport 993 -j ACCEPT
-A FORWARD -d 10.3.2.14/32 -p tcp -m tcp --dport 993 -j ACCEPT
COMMIT
# Completed on Thu Oct 2 09:37:25 2014
# Generated by iptables-save v1.4.8 on Thu Oct 2 09:37:25 2014
*nat
:PREROUTING ACCEPT [0:0]
:INPUT ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]
-A PREROUTING -d [b]<global-ip>[/b]/32 -p udp -m udp --dport 1194 -j DNAT --to-destination 10.3.2.14:1194
-A PREROUTING -d <hidden-global-ip>/32 -p tcp -m tcp --dport 465 -j DNAT --to-destination 10.3.2.14:465
-A PREROUTING -d <hidden-global-ip>/32 -p udp -m udp --dport 465 -j DNAT --to-destination 10.3.2.14:465
-A PREROUTING -d <hidden-global-ip>/32 -p udp -m udp --dport 993 -j DNAT --to-destination 10.3.2.14:993
-A PREROUTING -d <hidden-global-ip>/32 -p tcp -m tcp --dport 993 -j DNAT --to-destination 10.3.2.14:993
-A POSTROUTING -o eth0 -j MASQUERADE
-A POSTROUTING -s 10.3.2.0/24 -d 10.3.2.14/32 -p udp -m udp --dport 1194 -j SNAT --to-source 10.3.2.1
-A POSTROUTING -s 10.3.2.0/24 -d 10.3.2.14/32 -p tcp -m tcp --dport 465 -j SNAT --to-source 10.3.2.1
-A POSTROUTING -s 10.3.2.0/24 -d 10.3.2.14/32 -p udp -m udp --dport 465 -j SNAT --to-source 10.3.2.1
-A POSTROUTING -s 10.3.2.0/24 -d 10.3.2.14/32 -p udp -m udp --dport 993 -j SNAT --to-source 10.3.2.1
-A POSTROUTING -s 10.3.2.0/24 -d 10.3.2.14/32 -p tcp -m tcp --dport 993 -j SNAT --to-source 10.3.2.1
COMMIT
# Completed on Thu Oct 2 09:37:25 2014
Code: Select all
-A INPUT -i br0 -j ACCEPT